02 Patch applications (Essential)
Patch/mitigate computers with extreme risk vulnerabilities within 48 hours. Use the latest version of applications.
4
artefacts
2
held by a system
1
at each review
easy
to go live
Endpoint management (MDM / EDR)
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Configuration / tooling output demonstrating the strategy · Endpoint management (MDM / EDR)
- Records showing ongoing operation · Endpoint management (MDM / EDR)
periodic reviewEvidence produced at each review
- Evidence the mitigation strategy is implemented and maintained: Patch applications · Vulnerability scanner / patch tooling
governing documentDocuments that govern the control
- Coverage across in-scope systems · Policy repository / GRC workspace
First move
Automate the pull from your Endpoint management (MDM / EDR). Device compliance report from the MDM (encryption, EDR agent, OS version) on a daily pull.
Common gaps auditors find
- Strategy partially deployed (not all systems)
- No evidence of ongoing maintenance
- Effectiveness rating not met
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet01 Application control (Essential) · 03 Configure Microsoft Office macro settings (Essential)