Controls / Patching
Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: patch office software, browsers, email clients, PDF readers, security products and workstation operating systems within the times the rule sets.
In Australia
Maturity Level One
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1691 Essential Eight, Maturity Level One | Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release. Required at Maturity Levels One and Two of the Patch applications mitigation strategy (Appendices A and B); ISM control ISM-1691 in ASD's Essential Eight to ISM mapping (December 2023). At Maturity Level Three this requirement is replaced by ISM-1692 (48 hours when critical or exploited) and ISM-1901 (two weeks when non-critical). The requirement's own words: within two weeks of release evidence an assessor asks for Installed-version reports for office suites, browsers, email clients, PDF software and security products against vendor release dates; Deployment tool report showing successful installation within two weeks |
| ISM-1695 Essential Eight, Maturity Level One | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release. Required at Maturity Levels One and Two of the Patch operating systems mitigation strategy (Appendices A and B); ISM control ISM-1695 in ASD's Essential Eight to ISM mapping (December 2023). At Maturity Level Three this requirement is replaced by ISM-1696 (48 hours when critical or exploited) and ISM-1902 (one month when non-critical). The requirement's own words: within one month of release evidence an assessor asks for Hotfix listings (for example command-line output) with install dates for workstations and internal servers; Deployment compliance report showing application within one month |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 6.3.3 PCI DSS v4.0.1 (add-on) | Timely installation of security patches All system components must be shielded from known vulnerabilities by applying relevant security patches or updates such that: patches or updates addressing critical vulnerabilities, as ranked under Requirement 6.3.1, must go in within one month of their release; and every other relevant security patch or update is installed within a suitable time frame set by the entity's own assessment of how critical the risk is to its environment, using the Requirement 6.3.1 ranking process. It applies to all entities and all system components. Customized approach objective: exploitation of a known vulnerability cannot be used to compromise system components. The requirement's own words: within one month of their release evidence an assessor asks for Patch management procedure stating the one-month deadline for critical patches and time frames for others; Patch compliance reports per system component showing install dates against vendor release dates; Risk-based rationale or targeted risk analysis for non-critical patch time frames; Exception register for patches that could not be applied, with compensating measures; Sample of critical advisories traced to installation evidence |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 7.3 CIS Controls v8.1 | Perform Automated Operating System Patch Management Keep operating systems on enterprise assets updated by automated patch management, running at least once a month. The requirement's own words: at least once a month evidence an assessor asks for OS patch management tool configuration with automated monthly deployment; OS patch compliance reports per asset; Patch management standard defining monthly OS patch cycles and emergency patch windows; Deployment rings or maintenance window settings in the patching tool covering workstations and servers; Monthly OS patch deployment reports showing success rate and failed devices remediated |
| CIS 7.4 CIS Controls v8.1 | Perform Automated Application Patch Management Keep applications on enterprise assets updated by automated patch management, running at least once a month. The requirement's own words: at least once a month evidence an assessor asks for Application patch management configuration with automated monthly deployment; Application patch compliance reports; Patch standard covering third-party applications, not only operating system updates; Third-party patching tool catalogue showing which applications are auto-updated; Monthly application version compliance report for browsers, runtimes, PDF readers and office suites |
| PR.PS-02 NIST CSF 2.0 | Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Software lifecycle policy with end of support tracking; Patch management cadence and exception register; End of life replacement plan; Software risk assessments for unsupported tools; Software retirement records |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 6.3.3 PCI DSS v4.0.1 (add-on) | Timely installation of security patches All system components must be shielded from known vulnerabilities by applying relevant security patches or updates such that: patches or updates addressing critical vulnerabilities, as ranked under Requirement 6.3.1, must go in within one month of their release; and every other relevant security patch or update is installed within a suitable time frame set by the entity's own assessment of how critical the risk is to its environment, using the Requirement 6.3.1 ranking process. It applies to all entities and all system components. Customized approach objective: exploitation of a known vulnerability cannot be used to compromise system components. The requirement's own words: within one month of their release evidence an assessor asks for Patch management procedure stating the one-month deadline for critical patches and time frames for others; Patch compliance reports per system component showing install dates against vendor release dates; Risk-based rationale or targeted risk analysis for non-critical patch time frames; Exception register for patches that could not be applied, with compensating measures; Sample of critical advisories traced to installation evidence |
In United Kingdom
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SU.2 Cyber Essentials | Automatic Updates Enabled Where Possible Automatic updates must be enabled on devices and software where the option exists, to ensure security updates are applied without delay. evidence an assessor asks for Operating system automatic update policy; Automatic update setting on each desktop operating system; Update management or device management configuration |
| CE-SU.3 Cyber Essentials | Critical and High Updates within 14 Days All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release. The requirement's own words: within 14 days of release evidence an assessor asks for patch compliance dashboard from the patch or vulnerability management tool; 14-day SLA report; exception register |
PCI DSS v4.0.1, when it applies
Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| PCI DSS 6.3.3 PCI DSS v4.0.1 (add-on) | Timely installation of security patches All system components must be shielded from known vulnerabilities by applying relevant security patches or updates such that: patches or updates addressing critical vulnerabilities, as ranked under Requirement 6.3.1, must go in within one month of their release; and every other relevant security patch or update is installed within a suitable time frame set by the entity's own assessment of how critical the risk is to its environment, using the Requirement 6.3.1 ranking process. It applies to all entities and all system components. Customized approach objective: exploitation of a known vulnerability cannot be used to compromise system components. The requirement's own words: within one month of their release evidence an assessor asks for Patch management procedure stating the one-month deadline for critical patches and time frames for others; Patch compliance reports per system component showing install dates against vendor release dates; Risk-based rationale or targeted risk analysis for non-critical patch time frames; Exception register for patches that could not be applied, with compensating measures; Sample of critical advisories traced to installation evidence |
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.8 ISO/IEC 27001:2022 (lens) | Management of technical vulnerabilities The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8. evidence an assessor asks for Statement of Applicability entry for control A.8.8, showing inclusion or justified exclusion, implementation status and the risks it treats; A software asset inventory with vendor, product, version, deployment location and responsible owner; Defined vulnerability management roles and a list of monitored vulnerability information sources; Authenticated scan results and penetration test reports by authorized testers, with verification scans after patching; Remediation timelines by severity with measured performance, and risk records weighing the vulnerability against update risk |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 30 where its rule in the jurisdiction sets a timeframe of two weeks or less, otherwise day 60; day 90 when marked not sure or beyond the core list. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.