HLD Group
Patch management policy
Security patching cadence and emergency patch process.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy defines how HLD Group applies security and maintenance updates to systems, software, and dependencies in a timely and controlled manner. Patching is one of the most effective defences against exploitation of known vulnerabilities.
2. Scope
This policy applies to operating systems, firmware, applications, libraries, container images, and endpoints across the HLD Group estate.
3. Definitions
- Patch — an update that corrects a defect or vulnerability
- Patch window — a scheduled period for applying patches
- Out-of-band patch — an urgent patch applied outside the normal schedule
- End of life — the point after which a product no longer receives security updates
4. Policy statement
Systems and software are kept current with vendor security updates within timeframes commensurate with risk. Patching is coordinated with the Change Management Policy so that updates are tested and reversible, while security-critical patches are expedited.
5. Patch timeframes
- Critical and actively exploited vulnerabilities: patch on an expedited, out-of-band basis, targeting within 7 days
- High severity: within 30 days
- Medium severity: within 90 days
- Routine maintenance updates: within regular patch cycles
6. Testing and deployment
- Patches are tested in a non-production environment where feasible before broad deployment
- Automated patch deployment is used where safe, with staged rollout and monitoring
- Rollback plans exist for patches that could disrupt service
- Emergency patches follow the emergency change path with retrospective review
7. End-of-life and unsupported software
Software approaching end of life is identified and replaced or upgraded before support ends. Where unsupported software cannot be immediately retired, compensating controls and a documented risk acceptance with an expiry date are required.
8. Framework alignment
- ISO/IEC 27001:2022 Annex A control 8.8 (management of technical vulnerabilities)
- NIST SP 800-53 Rev. 5 control SI-2 (flaw remediation)
- SOC 2 Trust Services Criteria CC7.1
- PCI DSS v4.0 Requirement 6 where cardholder data is in scope
9. Roles, exceptions, and review
Patching is owned by IT and infrastructure under the CISO, with application owners responsible for their dependencies. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually.
Related frameworks
For contractual attestations or audit packs, contact [email protected].