# SP-038 Vulnerability Management and Patching

Status: active. Release 26.02. Modified 2026-02-07. Licence: CC BY-SA 4.0.

Scope: End-to-end vulnerability management pattern covering asset discovery, vulnerability scanning, risk-based prioritisation, patch management lifecycle, exception handling, metrics and reporting, and the organisational challenge of keeping pace with the relentless flow of new vulnerabilities. Addresses the operational reality that vulnerability management is not a project but a permanent capability that must balance...
Use when: This pattern applies to every organisation that operates technology -- vulnerability management is not optional. It is particularly critical for: organisations with internet-facing systems where unpatched vulnerabilities are directly exploitable, regulated industries where vulnerability management is explicitly required (PCI DSS Requirement 6, DORA ICT risk management, FCA operational resilience), organisations with...
Not when: There are no contraindications for vulnerability management -- every organisation needs it.

## Controls (25, NIST SP 800-53 ids)
- Critical (6): CA-07, CM-03, CM-08, RA-03, RA-05, SI-02
- Important (12): CA-02, CM-02, CM-04, CM-06, PM-05, PM-09, PM-14, PM-16, RA-02, SA-09, SC-07, SI-04
- Standard (7): CA-08, CM-07, AU-06, PL-02, SA-10, SA-11, SR-03

## What each critical control mitigates (6)
- CA-07 Continuous Monitoring: T-VM-001, T-VM-011, T-VM-012
- CM-03 Configuration Change Control: T-VM-002, T-VM-010
- CM-08 System Component Inventory: T-VM-005, T-VM-009
- RA-03 Risk Assessment: T-VM-006
- RA-05 Vulnerability Monitoring and Scanning: T-VM-001, T-VM-002, T-VM-003, T-VM-004, T-VM-005, T-VM-007, T-VM-009, T-VM-011, T-VM-012
- SI-02 Flaw Remediation: T-VM-001, T-VM-002, T-VM-003, T-VM-004, T-VM-010

## Threats and the controls that mitigate them (12)
- T-VM-001 Exploitation of known unpatched vulnerability on internet-facing system: RA-05, SI-02, SC-07, CA-07
- T-VM-002 Ransomware deployment via unpatched VPN appliance or remote access gateway: RA-05, SI-02, PM-16, CM-03
- T-VM-003 Lateral movement exploiting unpatched internal systems after initial access: RA-05, SI-02, SC-07, SI-04
- T-VM-004 Data breach through exploitation of vulnerable web application or API: RA-05, SI-02, SA-11, CA-08
- T-VM-005 Supply chain compromise via vulnerable third-party library or component: RA-05, SA-09, SR-03, CM-08
- T-VM-006 Exploitation of end-of-life system with no available security patches: RA-03, CA-02, SC-07, SI-04
- T-VM-007 Configuration vulnerability exploitation (default credentials, unnecessary services): CM-06, CM-02, RA-05, CM-07
- T-VM-008 Zero-day exploitation before vendor patch availability: CA-02, SC-07, SI-04, PM-16
- T-VM-009 Shadow IT systems unscanned and unpatched outside vulnerability management scope: CM-08, RA-05, PM-05, SI-04
- T-VM-010 Patch deployment causing operational outage due to insufficient testing: CM-04, CM-03, SI-02, CM-02
- T-VM-011 Container image vulnerability deployed at scale across orchestrated environment: RA-05, SA-10, CM-02, CA-07
- T-VM-012 Regulatory non-compliance due to demonstrably inadequate vulnerability management: RA-05, PM-14, CA-07, PM-05

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-038/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-038/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 33 KB: /api/v1/patterns/SP-038
- Page for people: /patterns/sp-038/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-012 Secure Software Development Lifecycle; SP-028 Secure DevOps Pipeline; SP-031 Security Monitoring and Response; SP-035 Offensive Security Testing; SP-036 Incident Response

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
