Patch management: why ML2 requires more than a scanning tool
Practice 2 — patch operating systems — and Practice 3 — patch applications — are among the most assessed Essential Eight strategies. Many organisations have tools in place but still stall at ML1.
The ML1 trap
Having a vulnerability scanner that produces weekly reports satisfies the baseline. ML2 requires evidence that patches are applied within ACSC timeframes and that exceptions are managed formally.
What assessors scrutinise
- Extreme risk vulnerabilities patched within 48 hours
- High risk within two weeks
- Documented exceptions with compensating controls and expiry dates
- Measured compliance rates — not just ticket counts
Moving forward
Start measuring your actual patch compliance rate per severity tier. If you cannot report that number today, that is your first remediation priority — before buying another scanning tool.