This template establishes how quickly patches get applied based on severity, and who’s responsible for making it happen. See our guide on patch management vs. mitigation for when to patch versus mitigate.
1. Purpose
This policy establishes timelines and responsibilities for applying security patches across [Organization Name] systems.
2. Patch Severity Timelines
- Critical: Applied within [24-72 hours] of release
- High: Applied within [7 days]
- Medium: Applied within [30 days]
- Low: Applied during the next scheduled maintenance window
3. Roles and Responsibilities
[IT/Security team] is responsible for identifying available patches, testing, and deployment. [System owners] are responsible for approving maintenance windows for their systems.
4. Testing Requirements
Patches for [production/critical systems] must be tested in a staging environment before deployment, except where the Emergency Patching Process applies.
5. Emergency Patching
For actively exploited vulnerabilities, standard testing requirements may be expedited or waived with approval from [approver], prioritizing rapid remediation over standard change control.
6. Systems Unable to Be Patched
Where a patch cannot be applied within the required timeline, compensating controls (network segmentation, additional monitoring) must be documented and approved by [approver].
7. Tracking and Reporting
Patch status is tracked in [tool/system] and reported to [leadership/committee] on a [monthly] basis.
Want this built and implemented for your organization?
A template is a starting point. Cyberix builds, customizes, and maintains policies like this as part of a full GRC engagement.
