PATCHOS-ML3 Patch Operating Systems (ML3)
All ML2 requirements plus: A vulnerability scanner is used at least fortnightly to identify missing patches in drivers and in firmware. Patches for drivers and firmware are applied within 48 hours of release when critica
8
artefacts
2
held by a system
3
at each review
moderate
to go live
Vulnerability scanner / patch tooling
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Fortnightly driver and firmware scan results from vendor tools (Dell Command Update, HP Image Assistant, Lenovo Vantage, server iLO/iDRAC, network device vendor advisories) · Vulnerability scanner / patch tooling
- Threat intelligence to patch workflow link (CISA KEV subscription, vendor PSIRT, ASD alerts) · Vulnerability scanner / patch tooling
periodic reviewEvidence produced at each review
- Driver and firmware patch deployment evidence with CVE-to-deployment timestamps within SLA · Vulnerability scanner / patch tooling
- Emergency patching evidence for non-internet-facing servers and workstations within 48 hours for critical CVEs · Vulnerability scanner / patch tooling
- Quarterly executive report showing N or N-1 OS adherence percentage · Vulnerability scanner / patch tooling
governing documentDocuments that govern the control
- OS version inventory confirming all hosts are on the latest or N-1 OS release · Policy repository / GRC workspace
- Replacement evidence (decommissioning tickets, migration plans) for any out-of-support OS · Policy repository / GRC workspace
- Coverage report for drivers across all hardware models and firmware across UEFI, BIOS, BMC, network device OS · Policy repository / GRC workspace
First move
Start with the 2 of 8 artefacts that already live in a system (Vulnerability scanner / patch tooling); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Driver and firmware patching done opportunistically at hardware refresh only
- 48-hour SLA met for internet-facing but not internal critical workloads
- OS version drift (e.g. Windows 10 22H2 retained alongside Windows 11) with no clear N-1 boundary
- Network device firmware lagging due to maintenance window scarcity
- Driver vulnerability scanning depends on vendor agent not installed across fleet
- EOL OS replacement plan slipped without re-baselining
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPATCHOS-ML2 Patch Operating Systems (ML2) · UAH-ML1 User Application Hardening - Maturity Level 1