Vulnerability Management

Establish a Vulnerability & Patch Management Program

Use built-in update tools first, then prioritize exposed and actively exploited weaknesses using business context.

Content review: 2026-09-22 · Estimated effort: High

Priority and effort are editorial starting points, not calculated risk or mandatory deadlines. Adapt to business impact, vendor instructions, available licenses, and applicable obligations. Test changes before broad rollout.

Before you start

Before starting: identify critical services, change approvers, backups, and recovery options. Plan for restarts and business disruption.

Put it into practice

  1. Use supported automatic updates where appropriate for operating systems, browsers, applications, and network equipment, including non-Windows systems. Retire or isolate unsupported products.
  2. Compare vendor advisories and CISA KEV entries with your inventory. Consider active exploitation, exposure, privileges, and business impact together; a severity score alone is not organizational risk.
  3. Assign risk-based deadlines and owners. Federal KEV deadlines are not universal SMB deadlines; check obligations that apply to you.
  4. Pilot updates on representative systems. For urgent exploitation when patching is unsafe or unavailable, assess vendor mitigations or temporary isolation. Record exceptions and review dates.
  5. Verify: check installed versions and restart status against the advisory, then confirm business services work. A successful deployment job alone is not proof that a fix took effect.

Make a start

Tools and templates

Start with what you already have. “Included” means part of an existing eligible product or subscription, not a free standalone service. Options reviewed 2026-09-22; check current vendor terms before choosing.

Start without another software subscription

Use supported Windows Update capabilities, vendor update instructions and the free CISA catalog with the patch worksheet.

Where this stops: Central deployment tools, extended support and some application updates can cost extra. A free catalog does not scan devices or prove that a patch was installed.

See the official sources and eligibility details below. Free software can still require equipment, storage and staff time.

Windows Update client policies

No extra service charge on supported Pro, Education and Enterprise editions

Start with Windows Update and use the documented Group Policy settings where supported to plan a pilot and rollout. Track actual versions and restart status.

Limits: Intune and other management products may require separate licenses. This does not update every third-party app. Confirm OS support and any extended-update entitlement rather than assuming all Windows 10 devices still receive free fixes.

Your information: Windows communicates with Microsoft update services. Management/reporting services may also receive device information when configured.

Official instructions: Windows Update client policies ↗

CISA Known Exploited Vulnerabilities catalog

Free public reference

Match listed vulnerabilities against your inventory and vendor advisories before deciding which updates or mitigations apply.

Limits: Not a scanner or a complete vulnerability list. Federal remediation deadlines are not automatically deadlines for your business.

Your information: Read or download the public catalog; you do not need to submit your inventory.

Official instructions: CISA Known Exploited Vulnerabilities catalog ↗

Download a working template

Free to download and adapt for your team. Open CSV files in Microsoft Excel using your existing Office license; Markdown files open in a text editor such as Notepad. Save an Excel Workbook (.xlsx) copy if you add formatting. These are manual worksheets, with no macros, scoring or automatic verification.

Fictional worked example

Illustration only. This is not a customer story, lab result, or evidence that your environment is protected. Replace the example entries and record your own observations.

A team plans an update for an office laptop used by its invoicing application.

Use the Patch and exception tracker template.

What to enter before testing

Asset or service reference
EXAMPLE-LAPTOP-02
Current version
Record observed version before change
Pilot and recovery plan reference
Pending: approved maintenance and recovery plan
Business service test result
Not tested

How to verify

Check the actual vendor advisory and applicable supported version. After an authorized pilot, confirm installed version and required restart, then open the invoicing application and run an approved non-production workflow. Record actual evidence, not just an update download.

If the result is unexpected

If installation fails or the workflow breaks, pause wider deployment and follow the approved vendor-supported recovery plan. Track any remaining exposure with an owner and time-bounded exception; a successful pilot does not prove every device is updated.

Save completed worksheets privately. They can describe security gaps, systems and people. Do not include passwords, recovery keys or confidential message content. This site does not receive your edits; a cloud editor or synced folder may send them to its provider.

Sources and review approach

Original small-team guidance with selected NIST CSF 2.0 alignments, not an official crosswalk or a complete framework implementation. These instructions are a starting point, not a claim of testing in your environment.

  • NIST CSF 2.0: ID.RA-01: vulnerability identification
  • NIST CSF 2.0: PR.PS-02: software maintenance
How this guidance is prepared