Patch management
Producing patch evidence for an audit
Turning retained patch inventory into something an auditor accepts.
Last updated
Auditors rarely ask whether you patch. They ask you to demonstrate that you patched, on a defined set of machines, within a defined window, and to show what you did about the machines you missed. Those are evidence questions rather than technical ones, and the difference catches teams out.
AegisOne retains per-endpoint patch inventory, and that retained record is the substance of the answer. Combined with the action log — which records who dispatched which operation against which endpoint and when — it produces a defensible account of the estate's patch position over time rather than a snapshot of today.
Scope the evidence to the client and date range the auditor named, not to your whole estate. Over-scoped evidence is not generous; it invites questions about machines that were never in scope and lengthens the engagement for no benefit.
Expect the exceptions to attract the most attention. Every real estate has machines that could not be patched in the window: a server with a change freeze, a laptop that was offline for a month, a device with a vendor-pinned version. The evidence should show that these were identified rather than missed. An estate with fourteen documented exceptions reads as controlled; an estate with none reads as either unusually fortunate or incompletely reported, and auditors have seen enough of the latter to check.
Reports generated from the catalogue export to PDF, Excel and PowerPoint. PDF is the right format for the evidence pack itself; Excel is what the auditor will actually want when they start sampling machines, because they will want to filter and sort. Provide both and you will typically avoid a second request.
The reporting layer is described in more detail under Reporting, and the compliance evidence collection that sits alongside it under Security.