Despite widespread recognition that patching is effective and attackers regularly exploit unpatched software, many organizations do not adequately patch. There are myriad reasons why, not the least of which are that it's resource-intensive and that the act of patching can reduce system and service availability. Also, many organizations struggle to prioritize patches, test patches before deployment, and adhere to policies for how quickly patches are applied in different situations. To address these challenges, the NCCoE is collaborating with cybersecurity technology providers to develop an example solution that addresses these challenges. This NIST Cybersecurity Practice Guide explains how tools can be used to implement the patching and inventory capabilities organizations need to handle both routine and emergency patching situations, as well as implement workarounds, isolation methods, or other alternatives to patching. It also explains recommended security practices for patch management systems themselves.
Document Citations
Citations are generated automatically from bibliographic data
as a convenience and may not be complete or accurate.
Chicago
National Institute of Standards and Technology (NIST), Commerce Department. "Improving Enterprise Patching for General IT Systems: Utilizing Existing Tools and Performing Processes in Better Ways". Government. Commerce Department, April 6, 2022. https://www.govinfo.gov/app/details/GOVPUB-C13-f298f21335fbb212758ced00bf389943
APA
National Institute of Standards and Technology (NIST), Commerce Department. (2022, April 6). Improving Enterprise Patching for General IT Systems: Utilizing Existing Tools and Performing Processes in Better Ways. [Government]. Commerce Department. https://www.govinfo.gov/app/details/GOVPUB-C13-f298f21335fbb212758ced00bf389943
MLA
National Institute of Standards and Technology (NIST), Commerce Department. Improving Enterprise Patching for General IT Systems: Utilizing Existing Tools and Performing Processes in Better Ways. Commerce Department, (6 Apr 2022), https://www.govinfo.gov/app/details/GOVPUB-C13-f298f21335fbb212758ced00bf389943
Bluebook
National Institute of Standards and Technology (NIST), Commerce Department, Improving Enterprise Patching for General IT Systems, GovInfo, (April 6, 2022), https://www.govinfo.gov/app/details/GOVPUB-C13-f298f21335fbb212758ced00bf389943