Vulnerability Management
Establish a Vulnerability & Patch Management Program
Use built-in update tools first, then prioritize exposed and actively exploited weaknesses using business context.
Content review: 2026-09-22 · Estimated effort: High
Priority and effort are editorial starting points, not calculated risk or mandatory deadlines. Adapt to business impact, vendor instructions, available licenses, and applicable obligations. Test changes before broad rollout.
Before you start
Before starting: identify critical services, change approvers, backups, and recovery options. Plan for restarts and business disruption.
Put it into practice
- Use supported automatic updates where appropriate for operating systems, browsers, applications, and network equipment, including non-Windows systems. Retire or isolate unsupported products.
- Compare vendor advisories and CISA KEV entries with your inventory. Consider active exploitation, exposure, privileges, and business impact together; a severity score alone is not organizational risk.
- Assign risk-based deadlines and owners. Federal KEV deadlines are not universal SMB deadlines; check obligations that apply to you.
- Pilot updates on representative systems. For urgent exploitation when patching is unsafe or unavailable, assess vendor mitigations or temporary isolation. Record exceptions and review dates.
- Verify: check installed versions and restart status against the advisory, then confirm business services work. A successful deployment job alone is not proof that a fix took effect.
Make a start
Tools and templates
Start with what you already have. “Included” means part of an existing eligible product or subscription, not a free standalone service. Options reviewed 2026-09-22; check current vendor terms before choosing.
Start without another software subscription
Use supported Windows Update capabilities, vendor update instructions and the free CISA catalog with the patch worksheet.
Where this stops: Central deployment tools, extended support and some application updates can cost extra. A free catalog does not scan devices or prove that a patch was installed.
See the official sources and eligibility details below. Free software can still require equipment, storage and staff time.
Windows Update client policies
No extra service charge on supported Pro, Education and Enterprise editions
Start with Windows Update and use the documented Group Policy settings where supported to plan a pilot and rollout. Track actual versions and restart status.
Limits: Intune and other management products may require separate licenses. This does not update every third-party app. Confirm OS support and any extended-update entitlement rather than assuming all Windows 10 devices still receive free fixes.
Your information: Windows communicates with Microsoft update services. Management/reporting services may also receive device information when configured.
Official instructions: Windows Update client policies ↗CISA Known Exploited Vulnerabilities catalog
Free public reference
Match listed vulnerabilities against your inventory and vendor advisories before deciding which updates or mitigations apply.
Limits: Not a scanner or a complete vulnerability list. Federal remediation deadlines are not automatically deadlines for your business.
Your information: Read or download the public catalog; you do not need to submit your inventory.
Official instructions: CISA Known Exploited Vulnerabilities catalog ↗Download a working template
Free to download and adapt for your team. Open CSV files in Microsoft Excel using your existing Office license; Markdown files open in a text editor such as Notepad. Save an Excel Workbook (.xlsx) copy if you add formatting. These are manual worksheets, with no macros, scoring or automatic verification.
- Patch and exception tracker (CSV) ↓
Track affected systems, vendor advice, exposure, pilot results, installed-version verification and approved exceptions.
Fictional worked example
Illustration only. This is not a customer story, lab result, or evidence that your environment is protected. Replace the example entries and record your own observations.
A team plans an update for an office laptop used by its invoicing application.
Use the Patch and exception tracker template.
What to enter before testing
- Asset or service reference
- EXAMPLE-LAPTOP-02
- Current version
- Record observed version before change
- Pilot and recovery plan reference
- Pending: approved maintenance and recovery plan
- Business service test result
- Not tested
How to verify
Check the actual vendor advisory and applicable supported version. After an authorized pilot, confirm installed version and required restart, then open the invoicing application and run an approved non-production workflow. Record actual evidence, not just an update download.
If the result is unexpected
If installation fails or the workflow breaks, pause wider deployment and follow the approved vendor-supported recovery plan. Track any remaining exposure with an owner and time-bounded exception; a successful pilot does not prove every device is updated.
Save completed worksheets privately. They can describe security gaps, systems and people. Do not include passwords, recovery keys or confidential message content. This site does not receive your edits; a cloud editor or synced folder may send them to its provider.
Sources and review approach
Original small-team guidance with selected NIST CSF 2.0 alignments, not an official crosswalk or a complete framework implementation. These instructions are a starting point, not a claim of testing in your environment.
- NIST CSF 2.0: ID.RA-01: vulnerability identification
- NIST CSF 2.0: PR.PS-02: software maintenance
- https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog ↗