patch-management
-
A Practical SMB Patch Cadence: Risk-Based Triage Without a SOC
6 min read
A one- to three-person IT team cannot patch every CVE. Here is a risk-based cadence using CISA KEV and EPSS, mapped to ISO 27001:2022 controls A.8.8 and A.8.9, that keeps the business stable and the auditor satisfied.
-
A Practical SMB Patch Cadence: Risk-Based Triage Without a SOC
A one- to three-person IT team cannot patch every CVE. Here is a risk-based cadence using CISA KEV and EPSS, mapped to ISO 27001:2022 controls A.8.8 and A.8.9, that keeps the business stable and the auditor satisfied.