Controls / Patching
Other business applications are patched within the timeframe in the requirement
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: patch the other business applications within the time the rule sets.
In Australia
Maturity Level Two
Above the target when the underwriter picks Maturity Level One: shown as "above your target level", never a gap.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1693 Essential Eight, Maturity Level Two | Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release. Required at Maturity Levels Two and Three of the Patch applications mitigation strategy (Appendices B and C); ISM control ISM-1693 in ASD's Essential Eight to ISM mapping (December 2023). The requirement's own words: within one month of release evidence an assessor asks for Patch records for other applications showing application within one month of release; Vendor release tracking for line-of-business applications |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 7.4 CIS Controls v8.1 | Perform Automated Application Patch Management Keep applications on enterprise assets updated by automated patch management, running at least once a month. The requirement's own words: at least once a month evidence an assessor asks for Application patch management configuration with automated monthly deployment; Application patch compliance reports; Patch standard covering third-party applications, not only operating system updates; Third-party patching tool catalogue showing which applications are auto-updated; Monthly application version compliance report for browsers, runtimes, PDF readers and office suites |
| PR.PS-02 NIST CSF 2.0 | Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Software lifecycle policy with end of support tracking; Patch management cadence and exception register; End of life replacement plan; Software risk assessments for unsupported tools; Software retirement records |
In United Kingdom
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SU.3 Cyber Essentials | Critical and High Updates within 14 Days All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release. The requirement's own words: within 14 days of release evidence an assessor asks for patch compliance dashboard from the patch or vulnerability management tool; 14-day SLA report; exception register |
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.8 ISO/IEC 27001:2022 (lens) | Management of technical vulnerabilities The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8. evidence an assessor asks for Statement of Applicability entry for control A.8.8, showing inclusion or justified exclusion, implementation status and the risks it treats; A software asset inventory with vendor, product, version, deployment location and responsible owner; Defined vulnerability management roles and a list of monitored vulnerability information sources; Authenticated scan results and penetration test reports by authorized testers, with verification scans after patching; Remediation timelines by severity with measured performance, and risk records weighing the vulnerability against update risk |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 30 where its rule in the jurisdiction sets a timeframe of two weeks or less, otherwise day 60; day 90 when marked not sure or beyond the core list. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.