Perform operating system updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
The organization has defined a process for addressing identified technical vulnerabilities.
Some vulnerabilities can be fixed directly, but vulnerabilities that have a significant impact should also be documented as security incidents. Once a vulnerability with significant impacts has been identified:
The organisation should have an adequate patch management procedure defined and implemented. This should include the testing and installation of patches.
There should measures to minimize the risk related to patch management and verification of successful installation of patches.
The patch management should be automated when possible (for example operating system updates).
The patch management process should take into account the requirements set by frameworks or other requiremetns they need to comply with.