Patch Management
Patch management is the controlled process of finding, prioritizing, testing, deploying, and verifying software and firmware updates across an organization. It reduces security and reliability risk while keeping changes within acceptable service limits.
itInfrastructure and operations | OpenSkills.info
Intro
Patch management as preventive maintenance
Patch management is the controlled process of identifying, prioritizing, acquiring, testing, deploying, and verifying software and firmware updates across an organization. A patch changes an existing product to correct a defect, close a vulnerability, improve stability, or maintain vendor support. The work covers operating systems, applications, libraries, device firmware, virtual machines, cloud workloads, network appliances, and other managed technology.
The patch file is only one input. Enterprise patch management is a maintenance system that connects vendor information, asset knowledge, risk decisions, change control, deployment technology, and evidence. NIST frames this system as preventive maintenance: it is an ongoing cost of operating technology, not an exceptional security project.
The operating loop
A durable patch program follows a closed loop:
inventory → monitor → assess → prioritize → acquire → test
↑ ↓
verify ← report ← handle exceptions ← deploy in stages
Inventory establishes what exists, which software it runs, who owns it, and which service depends on it. Monitoring collects vendor advisories, package metadata, security bulletins, and threat evidence. Assessment matches an update to affected assets and identifies prerequisites, supersedence, restart behavior, and possible service impact.
Prioritization decides what moves first. Acquisition obtains update content and metadata from trusted sources. Testing checks installation, application behavior, rollback or recovery procedures, and operational monitoring. Staged deployment moves from representative canaries to broader groups. Verification confirms the intended state on each target and checks that the service still works. Exceptions keep unresolved work visible until the update, a compensating control, replacement, or retirement removes the condition.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/40/r4/final
Supports
- Enterprise patch management as preventive maintenance
- Identifying, prioritizing, acquiring, installing, and verifying patches, updates, and upgrades
- Enterprise strategy, responsibilities, risk responses, and operational constraints
- Routine and emergency patching concepts
- https://csrc.nist.gov/pubs/sp/1800/31/final
Supports
- Asset inventory and automated assessment as patching foundations
- Prioritization, testing, deployment, verification, and emergency operations
- Isolation and other mitigations when immediate patching is not feasible
- Patch implementation evidence and enterprise reference architecture
- https://www.cisecurity.org/controls/continuous-vulnerability-management
Supports
- Documented risk-based remediation
- Automated operating-system and application patch management
- Asset and software inventory dependencies
- Continuous vulnerability tracking and remediation
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Supports
- Known exploitation as a vulnerability-management prioritization input
- The catalog as CISA's authoritative source for vulnerabilities exploited in the wild
- https://www.first.org/cvss/v4.0/specification-document
Supports
- CVSS Base, Threat, Environmental, and Supplemental metric groups
- Severity characteristics as distinct from complete local organizational risk
- https://learn.microsoft.com/en-us/intune/device-updates/windows/manage-update-rings
Supports
- Test, pilot, and production deployment stages
- Deferrals, restart settings, deadlines, active hours, and notifications
- Pause and uninstall behavior for update rings
- https://learn.microsoft.com/en-us/intune/device-updates/
Supports
- Intune update policies, rings, expedited deployments, drivers, and reporting
- Microsoft Intune and Windows Autopatch placement in the product landscape
- https://docs.aws.amazon.com/systems-manager/latest/userguide/patch-manager.html
Supports
- Patch policies, baselines, scan, and scan-and-install operations
- Managed nodes across cloud, edge, and on-premises systems
- AWS not testing patches and Patch Manager excluding major operating-system upgrades
- https://docs.cloud.google.com/compute/vm-manager/docs/patch/create-patch-job
Supports
- Patch job filters, windows, reboot controls, rollout order, and disruption budgets
- Small batches as an availability protection
- Pre-patch and post-patch scripts and status monitoring
- https://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/overview_concepts_and_deployment_considerations/content-and-patch-management-with-satellite_planning
Supports
- Repository synchronization, content management, hosts, and Capsule services
- Red Hat Satellite placement in controlled Linux content and patch management
- https://documentation.ubuntu.com/landscape/
Supports
- Ubuntu inventory, packages, repositories, updates, security patches, and reporting
- Canonical Landscape placement in Ubuntu fleet patching
- https://documentation.ubuntu.com/landscape/web-portal-manage-livepatch-and-kernel-updates/
Supports
- Distinction between installed kernel updates, running kernel state, restart requirements, and Livepatch state
- https://github.com/sindresorhus/awesome
Supports
- Awesome Sysadmin as a relevant curated ecosystem list
- https://github.com/awesome-foss/awesome-sysadmin
Supports
- Discovery of Rudder, opsi, Munki, aptly, Ansible, and Salt as relevant sysadmin ecosystem projects
- Curated categories for configuration management, deployment, asset management, and packaging
- https://docs.rudder.io/reference/9.2/plugins/system-updates.html
Supports
- Scheduled full and targeted update campaigns
- Centralized per-node results and repository-aware system updates
- https://docs.opsi.org/opsi-docs-en/4.3/index.html
Supports
- Operating-system installation, software distribution, inventory, and client patch management
- https://www.munki.org/munki/
Supports
- Repository-backed software installation and removal for managed macOS clients
- https://www.aptly.info/doc/overview/
Supports
- Debian repository mirrors, snapshots, filtering, and publication
- Repeatable and controlled package sets
- https://docs.ansible.com/ansible/latest/collections/ansible/builtin/package_module.html
Supports
- Portable package-state operations across managed hosts
- https://docs.saltproject.io/en/latest/ref/modules/all/salt.modules.pkg.html
Supports
- Package discovery, installation, upgrade, and version operations through Salt
- https://www.automox.com/platform/patching
Supports
- Cloud-controlled operating-system and third-party application patching
- Automox placement in distributed endpoint update orchestration
- https://help.hcl-software.com/bigfix/11.0/mcm/WebUI/Users_Guide/c_get_started_with_patch_policy.html
Supports
- Patch lists, schedules, deployment behavior, pre-caching, retries, and restart notification
- HCL BigFix placement in continuous enterprise endpoint patching
- https://www.ivanti.com/products/ivanti-neurons-for-patch-management
Supports
- Inventory, threat context, patch reliability, ring deployment, and compliance reporting
- Ivanti placement in risk-linked endpoint patch orchestration
- https://www.manageengine.com/patch-management/
Supports
- Endpoint scanning, patch testing, approval, deployment, restart, rollback, and compliance reporting
- ManageEngine placement across operating-system and third-party application patching
- https://www.tanium.com/blog/what-is-patch-management/
Supports
- Policy-based patch workflows and current endpoint intelligence
- Tanium placement in large distributed endpoint patching
- https://www.ninjaone.com/patch-management/
Supports
- Operating-system and application patch policies in a remote endpoint management platform
- NinjaOne placement for support-led patching and endpoint health workflows
- https://www.action1.com/
Supports
- Cloud-based vulnerability visibility and cross-platform patch deployment
- Action1 placement for distributed and intermittently connected endpoints
- https://www.qualys.com/docs/qualys-patch-management-getting-started-guide.pdf
Supports
- Vulnerability-linked patch assessment and deployment jobs through cloud agents
- Qualys placement in vulnerability-linked remediation
- https://www.microsoft.com/en-us/security/blog/2022/01/21/celebrating-20-years-of-trustworthy-computing/
Supports
- January 2002 launch of Trustworthy Computing
- Connection between the initiative and the first Patch Tuesday process
- https://csrc.nist.gov/pubs/sp/800/40/ver2/final
Supports
- August 2002 publication date of the original SP 800-40
- November 2005 publication and program focus of Version 2
- https://www.microsoft.com/en-us/msrc/blog/2013/10/10-years-of-update-tuesdays
Supports
- October 2003 announcement of a monthly security bulletin cadence
- Predictability as a customer requirement for patch timing
- https://www.first.org/cvss/v1/
Supports
- April 2005 selection of FIRST as CVSS custodian
- CVSS as a shared vulnerability severity language
- https://csrc.nist.gov/pubs/sp/800/40/r3/final
Supports
- July 2013 publication of the enterprise patch management technologies revision
- https://www.microsoft.com/en-us/security/blog/2017/05/12/wannacrypt-ransomware-worm-targets-out-of-date-systems/
Supports
- May 2017 WannaCrypt spread through systems missing an available SMB fix
- March 2017 availability of MS17-010 before the outbreak
- https://learn.microsoft.com/en-us/security-updates/Securitybulletins/2017/ms17-010
Supports
- March 14, 2017 publication date and SMB vulnerability scope of MS17-010
- https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_20211103.pdf
Supports
- November 2021 establishment and purpose of the Known Exploited Vulnerabilities Catalog
- Aggressive remediation based on evidence of active exploitation
- https://csrc.nist.gov/pubs/sp/800/40/r4/final
Supports
- The infographic restates only the saved intro, slides, and cheatsheet, whose operating-loop claims are grounded here and in the other listed sources
