← Glossary·Security

Patch Management

SOC 2ISO 27001HIPAAPCI DSS

Process of applying vendor security updates to systems within defined SLAs.

Patch Management is the disciplined application of vendor-issued security and stability updates to operating systems, runtimes, applications, and libraries — typically driven from vulnerability scan output and SLA-tracked.

Why it matters
Equifax 2017 ($700M+) was unpatched Apache Struts. Patch SLA misses remain the most cited control failure in post-breach OCR/AG investigations.

Related terms

Vulnerability Management
Continuous discover-prioritise-remediate cycle for software vulnerabilities (CVEs) and misconfigurations.
Change Management
Documented process for approving, testing, and deploying changes to production systems.

Does your program actually cover Patch Management?

Run a free ComplianceIQ audit against SOC 2 and we'll surface every gap on this — and the other controls auditors flag — with the exact clause references to fix.

Free SOC 2 auditBack to glossary