166 terms · 75/46/45
Defense № 023 · class: resilience

Patch Management

Patch management is the process of identifying, testing, and applying software updates that fix known vulnerabilities. The goal is to reduce the time window in which an attacker can exploit a known weakness.

Term

description · examples · notes

Patch management is the process of identifying, testing, and applying software updates that fix known vulnerabilities. The goal is to reduce the time window in which an attacker can exploit a known weakness.

Description

The process encompasses tracking vendor-released patches, risk and priority assessment, testing in a controlled environment, and planned deployment to production systems.

Regular patching is one of the most effective measures for reducing the attack surface, but it requires a disciplined process because unpatched systems remain vulnerable to known exploits.

What people often say

  • Annual patching is sufficient.
  • Patches can be applied without testing because they come from the vendor.

Covers / does not cover

Covers

  • Elimination of known vulnerabilities in operating systems and applications
  • Reduction of the attack surface available to adversaries
  • Systematic tracking of patching status across the entire infrastructure

Does not cover

  • Zero-day vulnerabilities for which no patch yet exists
  • System misconfigurations not related to software bugs
  • Protection against social engineering and phishing

Mentioned in the news

Composite

Threats

reduces 15

Techniques

neutralizes 8