Optizio Policy Documents

Optizio Endpoint Patch Management Policy

Introduction

This Patch Management Policy defines how Optizio keeps third-party (non-operating-system) software on endpoint systems up to date with vendor security patches. It exists because unpatched client-side applications, particularly those that render content from the internet, are a primary route to endpoint compromise.

Operating system patching is covered by section 8 of the Information Security Policy. Patching of application dependencies and server-side infrastructure is covered by the SDLC Policy.

Scope

This policy applies to all endpoint systems used to access Optizio systems, source code, or customer data, including laptops and workstations operated by employees and contractors. Optizio operates a small, remote-first estate of individually managed devices across Windows, macOS, and Linux. There is no on-premise managed client fleet.

1. Risk-Based Scope and Software Tiers

Optizio does not maintain an exhaustive item-by-item inventory of every package installed on every endpoint. Software is instead scoped into two tiers by exposure, and controls differ by tier.

Tier 1 — individually tracked. Software that renders, parses, or executes untrusted content originating from the internet, or that terminates a network connection. This is the software that attackers realistically target, and each item is verified by name and version at every review.

Tier 1 category Examples
Web browsers Google Chrome, Mozilla Firefox, Microsoft Edge, Safari
PDF readers Adobe Acrobat Reader, or the operating system’s native viewer
Email and calendar clients Desktop mail clients, where used in place of webmail
Messaging and conferencing Slack, Zoom, Microsoft Teams
Password managers Browser extensions and desktop applications
Endpoint protection Microsoft Defender, or equivalent anti-malware
Archive and compression utilities 7-Zip, WinRAR, The Unarchiver
Office and document suites Microsoft 365 applications, LibreOffice
Code editors and IDEs Visual Studio Code and similar, which open untrusted repositories and extensions
Container and VM runtimes Docker Desktop, where used to run third-party images
VPN and remote access clients Any client used to reach Optizio or customer systems

Tier 2 — managed at class level. All other software, including command-line utilities, developer tooling, language runtimes, and libraries installed through a package manager. Tier 2 software is not enumerated individually. It is required to be either self-updating or installed through a package manager, and is updated in bulk on the cadence defined in section 5.

2. Approved and Prohibited Software

3. Automatic Updates as the Primary Control

Automatic updating is the default and primary patch mechanism for all endpoint software.

4. Vulnerability Monitoring

5. Remediation Timelines

Timelines are measured from the vendor’s publication of a fix.

Severity Target
Actively exploited (CISA KEV listed, or public working exploit) Immediately, and no later than 72 hours
Critical (CVSS 9.0–10.0) Within 72 hours
High (CVSS 7.0–8.9) Within 7 days
Medium (CVSS 4.0–6.9) Within 30 days
Low (CVSS 0.1–3.9) Within 30 days, or the next routine update cycle
Tier 2 bulk update cycle Monthly

Where a patch cannot be applied within the target window, the software is removed, or its use is suspended, until a fix is available. If neither is possible, an exception is raised under section 7.

6. Verification and Evidence

7. Exceptions

8. Endpoint Separation from Production

Endpoint patching is one layer of defence rather than the primary protection for customer data.

9. Roles and Responsibilities

10. Policy Review

This policy is reviewed annually, or upon significant changes to the endpoint estate, business operations, or the threat landscape. Adoption of centralised device management would trigger a review of sections 3 and 6.

Updates are communicated to all relevant staff and stakeholders.