- Owner
- IT Security Manager
- Effective date
- September 15, 2026
- Review cycle
- Every 6 months
1.Purpose
To keep operating systems, applications and firmware current with security patches on a regular cadence, reducing exposure to known vulnerabilities while minimizing disruption to production systems.
2.Scope
Applies to patching servers, workstations, laptops and network devices, from advisory monitoring through testing, deployment and compliance verification, including expedited handling of critical vulnerabilities. Broader configuration changes follow the change management SOP.
Definitions
- Critical vulnerability
- A security flaw with a high likelihood of exploitation and severe impact, requiring expedited patching.
- Patch window
- The scheduled time during which patches are deployed to a group of systems.
- Patch ring
- A defined batch of systems that receive a patch together, often ordered from lowest to highest risk.
- Compliance rate
- The percentage of in-scope devices that have received a given patch.
3.Responsibilities
- System Administrator
- Tests patches, deploys them in batches, and remediates devices that miss the patch window.
- IT Security Manager
- Classifies patch severity, verifies compliance, and reports results.
- Change Manager
- Approves the patch deployment window as a standard or normal change.
- End User
- Restarts or makes their device available for patching when notified.
RACI matrix
| Activity | System Administrator | IT Security Manager | Change Manager | End User |
|---|---|---|---|---|
| Classify patch severity | C | R/A | I | - |
| Test patches before deployment | R/A | C | I | - |
| Approve the deployment window | C | C | R/A | I |
| Deploy and monitor patches | R/A | I | I | I |
| Verify and report patch compliance | R | R/A | I | - |
R = Responsible, A = Accountable, C = Consulted, I = Informed
4.Materials and PPE
Materials, tools and systems
- โPatch management console
- โVulnerability advisory feeds
- โTest or staging environment
- โPatch compliance dashboard
- โChange request for the patch cycle
5.Procedure
- 5.1
Monitor vulnerability advisories
System AdministratorThe System Administrator monitors vendor and vulnerability advisory feeds daily for newly released patches affecting in-scope systems.
- 5.2
Classify patch severity
IT Security ManagerThe IT Security Manager classifies each patch by severity, flagging any critical vulnerability for expedited handling outside the regular cycle.
Checkpoint: Every new advisory is reviewed and assigned a severity classification within one business day of release.
- 5.3
Test patches on non-production systems
System AdministratorThe System Administrator deploys the patch to a representative sample of non-production systems and checks for functional issues before wider rollout.
Warning: Never deploy an untested patch broadly to production, even under time pressure from a critical advisory.
- 5.4
Submit the patch cycle for approval
Change ManagerThe Change Manager approves the regular patch cycle as a standard change, or fast-tracks a critical patch through the expedited emergency change path.
- 5.5
Schedule and notify
System AdministratorThe System Administrator schedules the patch deployment window and notifies affected users of any expected restarts or downtime.
- 5.6
Deploy patches in batches
System AdministratorThe System Administrator deploys patches to production systems in defined rings, starting with lower-risk systems before moving to critical ones.
- 5.7
Monitor for post-patch issues
System AdministratorThe System Administrator monitors system health and the incident queue after each deployment ring for signs of a patch-related problem.
Checkpoint: No new critical incidents are linked to the deployment before the cycle is marked complete.
- 5.8
Roll back a problem patch
System AdministratorIf a patch causes a service-impacting issue, the System Administrator rolls it back on the affected systems immediately and pauses further rollout.
- 5.9
Verify patch compliance
IT Security ManagerThe IT Security Manager checks the patch management console to confirm which in-scope devices successfully received the patch.
- 5.10
Remediate missed devices
System AdministratorThe System Administrator follows up on devices that did not receive the patch within the defined grace period, such as offline laptops, and forces the update.
- 5.11
Document the cycle results
IT Security ManagerThe IT Security Manager documents the patch cycle results, including any exceptions and the final compliance rate.
- 5.12
Report compliance monthly
IT Security ManagerThe IT Security Manager reports patch compliance trends to the Change Manager and leadership on a monthly basis.
6.Quality checks
- โCritical vulnerabilities are patched within the defined expedited timeframe.
- โPatches are tested on non-production systems before broad deployment.
- โPatch compliance rate is tracked and reported on a monthly basis.
- โEvery patch cycle has a rollback path ready before deployment begins.
7.Records
- โPatch test results
- โChange request or approval for the patch cycle
- โPatch compliance report
- โRollback or incident record, if applicable
8.KPIs
- โPatch compliance rate across in-scope devices
- โMean time to patch critical vulnerabilities
- โNumber of rollbacks per patch cycle
- โPercentage of devices patched within the grace period
9.Common mistakes
- โDeploying a patch to every production system at once instead of using rings.
- โWaiting for the next monthly cycle to address a critical vulnerability.
- โNot tracking which devices missed the patch window.
- โHaving no rollback plan ready before deploying a patch.
10.Revision history
| Revision | Date | Description | Reviewed by |
|---|---|---|---|
| 1.0 | September 15, 2026 | Initial release | Ilia Pirozhenko |
This is a template. Adapt it to your organization, equipment and local regulations before use.