Knowledge / vulnerability hardening acsc-glossary

Patch

A vendor fix for a hole or a defect. Installing it is patching. Explaining why you did not is an exception with an expiry date.

VULNERABILITY MANAGEMENT LOOPDiscoverPrioritiseRemediateVerifyPrioritise with KEV, exposure, and asset value -- not CVSS alone.

A patch is software that repairs a vulnerability or improves behaviour of an application, operating system, or device. Patching is the act of putting it on. Unpatched software is code with known holes left open.

Internet-facing and known-exploited first. Hours and days, not quarters. Firmware and hypervisors count. A WAF or IPS rule while you wait is a seatbelt, not the destination.

Fact source: ASD's ACSC glossary.