EvidenceSheet

PATCHAPP-ML2 Patch Applications (ML2)

All ML1 requirements plus: A vulnerability scanner is used at least fortnightly to identify missing patches in applications other than office productivity suites, web browsers and their extensions, email clients, PDF sof

8
artefacts
3
held by a system
3
at each review
moderate
to go live
Vulnerability scanner / patch tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Fortnightly authenticated scan schedule covering all in-scope applications outside the ML1 priority classes · Vulnerability scanner / patch tooling
  • Scan results history with CVE coverage and last patched dates per host · Vulnerability scanner / patch tooling
  • Cross-reference between vulnerability scan output and patching system ticket queue · Vulnerability scanner / patch tooling

periodic reviewEvidence produced at each review

  • Patch deployment evidence showing CVE publication to deployment under 30 days for non-priority apps · Vulnerability scanner / patch tooling
  • Risk acceptance register for any patch deferred beyond SLA with executive sign-off and compensating control · Vulnerability scanner / patch tooling
  • Monthly patch compliance report by application class to CISO or risk forum · Vulnerability scanner / patch tooling

governing documentDocuments that govern the control

  • Patch management policy listing the in-scope application classes and SLAs · Policy repository / GRC workspace
  • Evidence that line-of-business and bespoke apps are in the scanner inventory · Policy repository / GRC workspace

First move

Start with the 3 of 8 artefacts that already live in a system (Vulnerability scanner / patch tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

PATCHAPP-ML1 Patch Applications (ML1) · PATCHAPP-ML3 Patch Applications (ML3)