PATCHAPP-ML3 Patch Applications (ML3)
All ML2 requirements plus: Patches or vendor mitigations for office productivity suites, web browsers and their extensions, email clients, PDF software and security products are applied within 48 hours of release when vu
8
artefacts
4
held by a system
2
at each review
easy
to go live
Vulnerability scanner / patch tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Threat intelligence feed configuration (CISA KEV, MSRC, vendor advisories) integrated with patching workflow · Vulnerability scanner / patch tooling
- Sample emergency patch tickets showing CVE publication, criticality decision, deployment to fleet within 48 hours · Vulnerability scanner / patch tooling
- Vendor mitigation register where a patch was not available but mitigation was applied (registry change, configuration change, firewall rule) · Vulnerability scanner / patch tooling
- Decommissioning evidence (change tickets, audit logs) for removed legacy applications · Vulnerability scanner / patch tooling
periodic reviewEvidence produced at each review
- Out-of-cycle change board records authorising emergency deployments · Vulnerability scanner / patch tooling
- Quarterly executive report showing 48-hour SLA compliance percentage · Vulnerability scanner / patch tooling
governing documentDocuments that govern the control
- Asset inventory showing no unsupported applications across the entire application estate · Policy repository / GRC workspace
- Coverage report showing every workstation, server and mobile device received the patch within SLA · Policy repository / GRC workspace
First move
Automate the pull from your Vulnerability scanner / patch tooling. Scan schedule, findings and remediation age straight from the scanner; patch compliance from the patch console.
Common gaps auditors find
- 48-hour SLA tracked but not met for remote or roaming workstations
- Browser extension patches missed because of dependency on user-driven updates
- Vendor mitigation applied but no record kept of when patch supersedes it
- Unsupported in-house apps tolerated indefinitely under risk acceptance
- Threat intelligence not linked to patch prioritisation
- Coverage report incomplete because mobile devices use separate patching tool
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPATCHAPP-ML2 Patch Applications (ML2) · PATCHOS-ML1 Patch Operating Systems (ML1)