Skip to main content

Pro audit program · v1.0

Patch Management Maturity

How fast are you patching workstations, servers, network gear and third-party apps? 8-question maturity check.

  • General target area
  • CIS Controls framework
  • 8 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

How fast are you patching workstations, servers, network gear and third-party apps? 8-question maturity check.

Risks addressed

  • Critical Unpatched workstation exploited via drive-by / phish
  • Critical Public-facing server compromised via known CVE
  • High Legacy systems remain unpatchable without compensating controls
  • High Network gear firmware lag introduces RCE / auth bypass risk

Controls (8)

  1. Patch policy with SLAs by severity

    High

    This control requires a documented patch management policy that defines mandatory service level agreements (SLAs) for remediation of vulnerabilities based on severity ratings (e.g., critical, high, medium, low). The policy specifies timeframes within which patches must be tested, approved, and…

    How to test + evidence

    Testing procedure: Review policy: critical <=7d, high <=14d, medium <=30d (or local equivalent).

    Evidence to collect: Policy document.

  2. Asset inventory drives patching scope

    High

    This control ensures that the organization's comprehensive asset inventory serves as the authoritative source for defining the scope of vulnerability management and patch deployment activities. All systems, applications, and network devices documented in the asset inventory must be included in…

    How to test + evidence

    Testing procedure: Confirm the asset inventory feeds the patch tool; no shadow devices.

    Evidence to collect: Inventory-to-patch crosswalk.

  3. Workstations patched within SLA

    High

    This control ensures that workstation operating systems and applications are updated with security patches within a defined service level agreement (SLA) timeframe, typically measured from the date a patch is released by the vendor or assessed as applicable to the…

    How to test + evidence

    Testing procedure: Pull patch compliance report for endpoints; >=95% within SLA over 90 days.

    Evidence to collect: Patch tool dashboard.

  4. Servers patched within SLA

    High

    This control ensures that servers are patched within a defined Service Level Agreement (SLA) timeframe, typically measured from the date a patch is released or identified as critical. Organizations establish risk-based patching windows (e.g., critical patches within 7 days, high…

    How to test + evidence

    Testing procedure: Same as above for server estate.

    Evidence to collect: Patch tool dashboard.

  5. Third-party app patching covered

    Medium

    This control ensures that third-party applications installed on organizational systems are included in the vulnerability management and patch management lifecycle. It requires inventorying all third-party software (browsers, PDF readers, Java runtime, media players, collaboration tools, developer utilities, etc.), monitoring vendor…

    How to test + evidence

    Testing procedure: Confirm browsers, Java, Adobe etc. are managed (not just OS).

    Evidence to collect: Software inventory + tool coverage.

  6. Network gear firmware patched

    Medium

    Network gear firmware patching ensures that routers, switches, firewalls, wireless access points, and other network infrastructure devices run current, vendor-supported firmware versions with known vulnerabilities remediated. Organizations maintain an inventory of network devices, track vendor security advisories, test firmware updates…

    How to test + evidence

    Testing procedure: Routers, switches, firewalls patched within vendor recommended cadence.

    Evidence to collect: Firmware version inventory.

  7. Exception process for unpatchable systems

    Medium

    This control establishes a formal exception and risk acceptance process for systems that cannot be patched due to technical constraints, vendor support limitations, or operational requirements. When vulnerabilities cannot be remediated through standard patching, the organization must document the business…

    How to test + evidence

    Testing procedure: Compensating controls + risk acceptance documented for any legacy systems.

    Evidence to collect: Exception register.

  8. Vulnerability scans verify patch state

    High

    This control validates that automated vulnerability scanning tools accurately detect and report the patch status of operating systems and applications across the organization's asset inventory. Scanners compare installed software versions against vulnerability databases and vendor security bulletins to identify missing…

    How to test + evidence

    Testing procedure: Authenticated scans confirm patch state matches the patch tool.

    Evidence to collect: Recent scan + reconciliation.