1
Monthly Triage Matrix
| # | CVE ID | Vendor | Product | CVSS | KEV | EPSS | Affected Assets | Priority | Sprint Day | Status |
|---|
Critical (9.0-10.0)
High (7.0-8.9)
Medium (4.0-6.9)
Low (0.1-3.9)
2
14-Day Sprint Calendar
Download & Review
Classify & Prep
Test
Deploy Critical
Deploy High
Deploy Remaining
Exceptions
Reporting
3
Testing & Rollback Checklist
Pre-Deployment
- Snapshot/backup of target systems taken
- Change request approved and documented
- Test environment mirrors production config
- Patch dependencies verified (Windows, Linux repos, firmware)
- Rollback procedure documented per platform
- Maintenance window communicated to stakeholders
- Monitoring alerts configured for deployment window
Deployment
- Patches applied in correct order
- System reboots completed (if required)
- Services restarted and confirmed running
- Patch installation verified (version check per OS)
- No new errors in event logs / syslog / journald
- Network connectivity confirmed
Post-Deployment
- Application functionality smoke test passed
- Performance baseline comparison — no degradation
- Security scan confirms vulnerability remediated
- User acceptance testing completed (critical apps)
- CMDB / asset inventory updated
- Monitoring returned to normal thresholds
Rollback Triggers
- Critical application fails to start
- Authentication / SSO broken
- Network connectivity loss (>5 min)
- Performance degradation >20% from baseline
- Data integrity issues detected
- Blue screen / kernel panic / boot failure on restart
- Rollback initiated — snapshot restored
4
SLA Compliance Tracker
| Severity | SLA | Total CVEs | Patched | Exceptions | Overdue | Compliance % |
|---|---|---|---|---|---|---|
| Critical | 48 hours | 0% | ||||
| High | 7 days | 0% | ||||
| Medium | 14 days | 0% | ||||
| Low | 30 days | 0% |
5
Executive Summary
Monthly Patch Management Report
Patches Applied
SLA Compliance
Exceptions
Rollbacks
Risk Summary
Exceptions & Justifications
Next Steps & Recommendations