PATCHAPP-ML1 Patch Applications (ML1)
An automated method of asset discovery is used at least fortnightly to support detection of assets for subsequent vulnerability scanning. A vulnerability scanner with an up-to-date vulnerability database is used. The sca
8
artefacts
3
held by a system
3
at each review
moderate
to go live
Vulnerability scanner / patch tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Asset discovery tool configuration (Tenable Nessus, Qualys, Rapid7 InsightVM, Microsoft Defender for Endpoint) showing fortnightly scheduled discovery scans · Vulnerability scanner / patch tooling
- Daily scan schedule and result history for online services (web apps, externally exposed APIs, internet-facing portals) · Vulnerability scanner / patch tooling
- Patch deployment evidence: tickets, change records or SCCM / Intune / Jamf reports correlating CVE publication date to patch deployment date for each in-scope class · Vulnerability scanner / patch tooling
periodic reviewEvidence produced at each review
- Vulnerability scanner plugin/feed last-updated timestamp evidence · Vulnerability scanner / patch tooling
- Weekly scan schedule and result history for the in-scope application classes · Vulnerability scanner / patch tooling
- List of online services with EOL/EOS status and decommissioning evidence · Policy repository / GRC workspace
governing documentDocuments that govern the control
- Endpoint software inventory showing no Adobe Flash, no unsupported browser versions, no out-of-support PDF readers · Policy repository / GRC workspace
- Vendor support lifecycle policy with explicit deadlines for replacement · Vendor register / contract repository
First move
Start with the 3 of 8 artefacts that already live in a system (Vulnerability scanner / patch tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Asset discovery cadence longer than fortnightly or run only when changes are requested
- Scanner credentialed scanning not configured, only unauthenticated scans, missing internal patch state
- Patching SLA met for Microsoft updates but missed for third-party apps (Chrome, Firefox, Adobe, Java, Zoom)
- Adobe Flash Player still installed on legacy systems
- Online services classed differently to ACSC definition, missing daily scan obligation
- Critical CVE patched but evidence of decision (critical vs non-critical) not retained
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetMFA-ML3 Multi-Factor Authentication - Maturity Level 3 · PATCHAPP-ML2 Patch Applications (ML2)