PATCHAPP-ML2 Patch Applications (ML2)
All ML1 requirements plus: A vulnerability scanner is used at least fortnightly to identify missing patches in applications other than office productivity suites, web browsers and their extensions, email clients, PDF sof
8
artefacts
3
held by a system
3
at each review
moderate
to go live
Vulnerability scanner / patch tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Fortnightly authenticated scan schedule covering all in-scope applications outside the ML1 priority classes · Vulnerability scanner / patch tooling
- Scan results history with CVE coverage and last patched dates per host · Vulnerability scanner / patch tooling
- Cross-reference between vulnerability scan output and patching system ticket queue · Vulnerability scanner / patch tooling
periodic reviewEvidence produced at each review
- Patch deployment evidence showing CVE publication to deployment under 30 days for non-priority apps · Vulnerability scanner / patch tooling
- Risk acceptance register for any patch deferred beyond SLA with executive sign-off and compensating control · Vulnerability scanner / patch tooling
- Monthly patch compliance report by application class to CISO or risk forum · Vulnerability scanner / patch tooling
governing documentDocuments that govern the control
- Patch management policy listing the in-scope application classes and SLAs · Policy repository / GRC workspace
- Evidence that line-of-business and bespoke apps are in the scanner inventory · Policy repository / GRC workspace
First move
Start with the 3 of 8 artefacts that already live in a system (Vulnerability scanner / patch tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Fortnightly scan runs but only covers Microsoft updates
- Bespoke or in-house developed apps excluded from scanning
- One-month SLA tracked but missed for line-of-business apps where vendor delivery is slow
- Risk acceptance approved verbally with no register
- Scan output not reconciled to patch deployment evidence (cannot prove every CVE was actioned)
- Vendor mitigations (configuration changes) used in lieu of patches but not documented
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPATCHAPP-ML1 Patch Applications (ML1) · PATCHAPP-ML3 Patch Applications (ML3)