A security operations team is establishing a standardized patch management workflow to ensure system security while minimizing operational disruption across the enterprise. Place the steps of the enterprise patch management lifecycle in the correct procedural sequence from initial identification to post-implementation audit.
- 1Analyze vulnerability intelligence feeds and prioritize missing vendor updates based on asset criticality.
- 2Apply and evaluate the updates within a non-production staging environment to verify system stability and application compatibility.
- 3Submit a formal change request to the Change Advisory Board (CAB) including deployment risk assessments and rollback plans.
- 4Execute a phased rollout of the updates across production systems during authorized maintenance windows.
- 5Perform automated security baseline auditing and vulnerability scanning to confirm successful remediation and drift prevention.
Answer
The correct procedural sequence for the patch management lifecycle is: (1) Analyze vulnerability intelligence feeds and prioritize missing vendor updates based on asset criticality; (2) Apply and evaluate the updates within a non-production staging environment to verify system stability and application compatibility; (3) Submit a formal change request to the Change Advisory Board (CAB) including deployment risk assessments and rollback plans; (4) Execute a phased rollout of the updates across production systems during authorized maintenance windows; and (5) Perform automated security baseline auditing and vulnerability scanning to confirm successful remediation and drift prevention.
The standard patch management lifecycle follows a structured progression: vulnerability identification and prioritization must occur first, followed by pre-deployment testing in staging to ensure stability. Once validated, formal approval from the Change Advisory Board (CAB) is sought with a documented rollback plan. Production deployment is then executed in a phased manner during scheduled maintenance windows, ending with post-patch auditing and baseline verification to confirm vulnerability remediation.
Step-by-Step Solution
Key Concept
Enterprise Patch Management Lifecycle