{"id":1205,"date":"2026-09-13T18:39:27","date_gmt":"2026-09-13T18:39:27","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1205"},"modified":"2026-09-13T18:39:27","modified_gmt":"2026-09-13T18:39:27","slug":"patch-management","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/patch-management\/","title":{"rendered":"Patch Management"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: PATCH MANAGEMENT\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Deploying a patch is the easy part. Knowing what you own, and proving the update actually landed on all of it, is where patch management fails.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Endpoint<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Patch management is the process of identifying missing software updates across everything you run, testing them, deploying them on a defined schedule, and verifying they applied. It is one remediation path within <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">vulnerability management<\/a>, and the one that covers most known vulnerabilities in practice.<\/p>\n<\/div>\n\n<p>Most breaches involving a known vulnerability involve one where a patch already existed. Patch management is therefore an operational discipline before it is a technical one.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#stages\">The five stages<\/a><\/li>\n    <li><a href=\"#versus\">Patching is not vulnerability management<\/a><\/li>\n    <li><a href=\"#fails\">Why patches do not get applied<\/a><\/li>\n    <li><a href=\"#auditors\">What auditors check<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"stages\">The five stages of patch management<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 178\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Five patch management stages: inventory, detect, test, deploy and verify.\">\n  <defs><marker id=\"pm\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"10\" y=\"24\" width=\"132\" height=\"72\" rx=\"12\" fill=\"#cfd5f2\"\/>\n  <text x=\"76\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">Inventory<\/text>\n  <text x=\"76\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">What do we own?<\/text>\n  <line x1=\"146\" y1=\"60\" x2=\"162\" y2=\"60\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#pm)\"\/>\n\n  <rect x=\"168\" y=\"24\" width=\"132\" height=\"72\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"234\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">Detect<\/text>\n  <text x=\"234\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">What is missing?<\/text>\n  <line x1=\"304\" y1=\"60\" x2=\"320\" y2=\"60\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#pm)\"\/>\n\n  <rect x=\"326\" y=\"24\" width=\"132\" height=\"72\" rx=\"12\" fill=\"#e3f0e9\"\/>\n  <text x=\"392\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">Test<\/text>\n  <text x=\"392\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Will it break us?<\/text>\n  <line x1=\"462\" y1=\"60\" x2=\"478\" y2=\"60\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#pm)\"\/>\n\n  <rect x=\"484\" y=\"24\" width=\"132\" height=\"72\" rx=\"12\" fill=\"#efe4f0\"\/>\n  <text x=\"550\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Deploy<\/text>\n  <text x=\"550\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Ship it, in waves<\/text>\n  <line x1=\"620\" y1=\"60\" x2=\"636\" y2=\"60\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#pm)\"\/>\n\n  <rect x=\"642\" y=\"24\" width=\"108\" height=\"72\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"696\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#a2603a\">Verify<\/text>\n  <text x=\"696\" y=\"73\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Did it land?<\/text>\n\n  <rect x=\"10\" y=\"114\" width=\"740\" height=\"48\" rx=\"12\" fill=\"#e9ecfa\"\/>\n  <text x=\"380\" y=\"135\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">Everyone runs the middle three. The first and last stages are the ones that decide whether it worked.<\/text>\n  <text x=\"380\" y=\"152\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#3f4796\">You cannot patch an asset you do not know about, and a deployment is not evidence of an install.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<p>Every patch management programme runs these five, whether or not anyone has named them.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Stage<\/th><th>What it involves<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Inventory<\/td><td>A current list of devices, servers, images and installed software. Without it, coverage figures are guesses<\/td><\/tr>\n    <tr><td>Detect<\/td><td>Comparing installed versions against available updates, usually through <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">scanning<\/a> or agent reporting<\/td><\/tr>\n    <tr><td>Test<\/td><td>Confirming the update does not break something. In practice most teams test on a small ring rather than a lab<\/td><\/tr>\n    <tr><td>Deploy<\/td><td>Rolling out in waves so a bad update affects a few machines rather than everyone<\/td><\/tr>\n    <tr><td>Verify<\/td><td>Confirming the version changed on each asset. This is what closes the loop, and the stage most often skipped<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"versus\" class=\"c-sage\">Patch management is not vulnerability management<\/h2>\n\n<p>The two get used interchangeably and they are not the same scope. Patching is one of several responses to a finding.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Response<\/th><th>When it is the right one<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Apply the patch<\/td><td>A fix exists, testing is feasible, and downtime is acceptable. The default<\/td><\/tr>\n    <tr><td>Change configuration<\/td><td>The vulnerable feature can be disabled without losing anything you use<\/td><\/tr>\n    <tr><td>Compensating control<\/td><td>No patch available or deployment is blocked, so exposure is reduced another way, such as filtering the request at the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web protection layer<\/a><\/td><\/tr>\n    <tr><td>Rebuild the image<\/td><td>Containers and ephemeral cloud instances. You replace the image rather than patch the running workload<\/td><\/tr>\n    <tr><td>Decommission<\/td><td>End-of-life software with no fix coming. Removal is the only real remediation<\/td><\/tr>\n    <tr><td>Accept the risk<\/td><td>Formally, with an owner and a review date. Not by silence<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability management<\/a> decides which of those applies and tracks it to closure. Patch management executes one of them well. Conflating the two produces a patch management programme that only ever handles the vulnerabilities that happen to have patches, and quietly ignores the rest.<\/p>\n\n<h2 id=\"fails\" class=\"c-plum\">Where patch management breaks down<\/h2>\n\n<p>Patch management rarely fails at the deployment step. It fails at the edges of the estate.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Reason<\/th><th>What it looks like<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>The unmanaged tail<\/td><td>Servers are patched centrally. Laptops, contractor machines, that one legacy virtual machine and the demo environment are not<\/td><\/tr>\n    <tr><td>Reboots<\/td><td>The patch installs but requires a restart. Users defer indefinitely, so the machine reports patched and remains vulnerable<\/td><\/tr>\n    <tr><td>Third-party applications<\/td><td>Operating system updates are automated. Browsers, runtimes, database clients and desktop tools each have their own updater<\/td><\/tr>\n    <tr><td>Fear of breakage<\/td><td>One bad update years ago produced a permanent culture of deferral, which is worse than the original risk<\/td><\/tr>\n    <tr><td>End of life<\/td><td>No patch is coming. The finding stays open forever because nobody wants to own the migration<\/td><\/tr>\n    <tr><td>Cloud images<\/td><td>Instances are patched but the base image is not, so every new deployment reintroduces the vulnerability<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Reported patched is not the same as patched<\/p>\n  <p>Two failure modes hide inside a healthy-looking dashboard. A pending reboot leaves the vulnerable code still running while the tool reports the update as installed. A stale base image means every fresh container or instance arrives with the flaw already present, no matter how diligently the running fleet was updated. Both are only caught at the verify stage, which is why verification against actual running versions matters more than deployment success rates.<\/p>\n<\/div>\n\n<h2 id=\"auditors\" class=\"c-sky\">What auditors check in patch management<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>What they ask for<\/th><th>Why it fails<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>A documented patching policy with timelines by severity<\/td><td>The policy exists but names no deadlines, so nothing can be measured against it<\/td><\/tr>\n    <tr><td>Evidence patches were applied within those timelines<\/td><td>Critical fixes sat open for months with no recorded reason<\/td><\/tr>\n    <tr><td>Coverage across the whole estate<\/td><td>The report covers servers only. Endpoints and cloud images are absent<\/td><\/tr>\n    <tr><td>An exception register<\/td><td>Deferrals are informal, with no owner, no compensating control and no review date<\/td><\/tr>\n    <tr><td>Emergency patching process<\/td><td>No defined path for an actively exploited flaw outside the normal cycle<\/td><\/tr>\n    <tr><td>Verification records<\/td><td>Deployment logs are supplied instead of proof the version actually changed<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> names a specific window for critical patches. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/nist-csf\/\">NIST CSF<\/a> ask you to define your own timelines and then evidence that you met them. Setting a realistic deadline and hitting it consistently evidences better than an ambitious one you routinely miss.<\/p>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Osto is not a patch deployment tool. It does not push operating system updates or replace the endpoint management platform that installs them, and that distinction is worth being clear about before a demo.<\/p>\n\n<p>What it covers is the rest of the patch management programme. The <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT scanner<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">vulnerability scanning<\/a> find what is missing and categorise it by severity, with retest reports that close the verify stage. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">Cloud posture management<\/a> covers the image and instance side. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">Software composition analysis<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> generation handle dependency versions in your own code, which no operating system updater reaches.<\/p>\n\n<p>For the gap between disclosure and deployment, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web and API protection<\/a> can filter exploitation attempts at the edge, which is the compensating control auditors expect to see documented against a deferral. Findings, remediation and retest evidence live in one place alongside <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> records, so the audit answer is one report rather than an export from four tools.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Findings, fixes and retests in one record<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Scanning across apps, cloud and dependencies, with edge filtering for the window before a fix ships and retest evidence an auditor will accept. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is patch management?<\/summary>\n  <p>Patch management is the process of finding missing software updates across your estate, testing them, deploying them on a defined schedule and verifying they applied. It covers operating systems, applications, firmware and cloud images.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between patch management and vulnerability management?<\/summary>\n  <p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability management<\/a> finds weaknesses, decides how to handle each one and tracks it to closure. Patch management executes one of those responses and evidences it. Configuration changes, compensating controls, image rebuilds and decommissioning are the others.<\/p>\n<\/details>\n\n<details>\n  <summary>How quickly should critical patches be applied?<\/summary>\n  <p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> sets a defined window for critical fixes. Other frameworks ask you to set your own timeline and evidence that you met it. A realistic deadline consistently met evidences far better than an aggressive one routinely missed.<\/p>\n<\/details>\n\n<details>\n  <summary>Do you patch containers?<\/summary>\n  <p>Not the running container. You rebuild the image with the updated package and redeploy, because a patch applied to a running container disappears at the next deployment. Patching the base image is the actual fix.<\/p>\n<\/details>\n\n<details>\n  <summary>What if no patch exists?<\/summary>\n  <p>Apply a compensating control and record it. Disable the vulnerable feature, restrict access, or filter exploitation attempts at the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web protection layer<\/a>. For end-of-life software with no fix coming, decommissioning is the only genuine remediation.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">Vulnerability Scanning<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/epp\/\">EPP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mdm\/\">MDM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Deploying a patch is the easy part. Knowing what you own, and proving the update actually landed on all of\u2026<\/p>\n","protected":false},"author":8,"featured_media":1206,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[201,605,606],"class_list":["post-1205","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-patch-management","tag-patch-management-process","tag-patch-management-vs-vulnerability-management"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1205"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1205\/revisions"}],"predecessor-version":[{"id":1207,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1205\/revisions\/1207"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1206"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1205"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}