2405.0—2405.0
>Control Description
The Supplier shall develop and maintain an appropriately robust patch management programme to address known vulnerabilities on its network within industry best-practice timelines. The Supplier shall take appropriate steps to identify, assess, test and implement patches for endpoints, network devices and software which address known vulnerabilities within industry best practice timeline.
The Supplier shall have appropriate processes in place to address out-of-band emergency patching and/or mitigating actions.
>Cross-Framework Mappings
Ask AI
Configure your API key to use AI features.