What CERT-In Actually Requires
CERT-In Directions 2022 requires organisations to implement a vulnerability management programme with defined timelines for critical patch deployment. The RBI Cybersecurity Framework for banks mandates that critical patches be applied within 30 days. ISO/IEC 27001:2022 Annex A.8.8 requires management of technical vulnerabilities. All three frameworks require a documented policy, not ad hoc patching.
Recommended Patch SLA by Severity — India Regulated Sectors
| Severity | CVSS Score | Target SLA | Framework Ref |
|---|---|---|---|
| Critical | 9.0 – 10.0 | 7 days | CERT-In, RBI |
| High | 7.0 – 8.9 | 15 days | CERT-In, ISO 27001 |
| Medium | 4.0 – 6.9 | 30 days | ISO 27001, CIS |
| Low | 0.1 – 3.9 | 90 days | CIS Controls v8 |
The 5-Stage Patch Management Process
- Identify: Automated vulnerability scanning (weekly minimum) using tools like Tenable Nessus or Qualys. Subscribe to vendor advisories and NIST NVD alerts.
- Assess: Prioritise using CVSS score, asset criticality, and exploitability. A critical vulnerability on a DMZ-facing server is not the same risk as on an isolated dev machine.
- Test: Deploy patches to non-production environments first. Document test results. Define rollback procedures before deploying to production.
- Deploy: Use change management approval for production patching. Maintain deployment records with timestamps, systems patched, and operator identity.
- Verify: Re-scan patched systems to confirm successful remediation. Close the vulnerability ticket only after verification scan shows clear.
What Auditors Look For as Evidence
Auditors will not accept "we patch regularly" as evidence. They expect: a written Patch Management Policy (version-controlled, board-approved), vulnerability scan reports showing before/after state, deployment logs with timestamps, exception registers for patches that cannot be applied, and an escalation path for zero-day events. Without documentation, even excellent patching practices fail the audit.
Is Your Patch Cycle Audit-Ready?
InfraVeritas 360 assesses your patch management policy, SLA adherence, evidence documentation, and exception register — and shows you exactly what a CERT-In or ISO 27001 auditor will find.
Assess Your Patch Programme →