Optizio Endpoint Patch Management Policy
Introduction
This Patch Management Policy defines how Optizio keeps third-party (non-operating-system) software
on endpoint systems up to date with vendor security patches. It exists because unpatched
client-side applications, particularly those that render content from the internet, are a primary
route to endpoint compromise.
Operating system patching is covered by section 8 of the Information Security Policy. Patching of
application dependencies and server-side infrastructure is covered by the SDLC Policy.
Scope
This policy applies to all endpoint systems used to access Optizio systems, source code, or
customer data, including laptops and workstations operated by employees and contractors. Optizio
operates a small, remote-first estate of individually managed devices across Windows, macOS, and
Linux. There is no on-premise managed client fleet.
1. Risk-Based Scope and Software Tiers
Optizio does not maintain an exhaustive item-by-item inventory of every package installed on every
endpoint. Software is instead scoped into two tiers by exposure, and controls differ by tier.
Tier 1 — individually tracked. Software that renders, parses, or executes untrusted content
originating from the internet, or that terminates a network connection. This is the software that
attackers realistically target, and each item is verified by name and version at every review.
| Tier 1 category |
Examples |
| Web browsers |
Google Chrome, Mozilla Firefox, Microsoft Edge, Safari |
| PDF readers |
Adobe Acrobat Reader, or the operating system’s native viewer |
| Email and calendar clients |
Desktop mail clients, where used in place of webmail |
| Messaging and conferencing |
Slack, Zoom, Microsoft Teams |
| Password managers |
Browser extensions and desktop applications |
| Endpoint protection |
Microsoft Defender, or equivalent anti-malware |
| Archive and compression utilities |
7-Zip, WinRAR, The Unarchiver |
| Office and document suites |
Microsoft 365 applications, LibreOffice |
| Code editors and IDEs |
Visual Studio Code and similar, which open untrusted repositories and extensions |
| Container and VM runtimes |
Docker Desktop, where used to run third-party images |
| VPN and remote access clients |
Any client used to reach Optizio or customer systems |
Tier 2 — managed at class level. All other software, including command-line utilities,
developer tooling, language runtimes, and libraries installed through a package manager. Tier 2
software is not enumerated individually. It is required to be either self-updating or installed
through a package manager, and is updated in bulk on the cadence defined in section 5.
2. Approved and Prohibited Software
- Software may only be installed on endpoints where it serves a legitimate business purpose.
- Software is obtained only from the vendor’s official distribution channel, an operating system
app store, or a reputable package manager. Third-party download aggregators are not permitted.
- Software that has reached end of life, or is no longer receiving vendor security updates, must
not be installed and is removed when identified.
- Adobe Flash Player is prohibited. It reached end of life on 31 December 2020 and is not
installed on any Optizio endpoint.
- Oracle Java Runtime Environment is not part of the standard endpoint build. It is not
installed unless a documented business need exists, and any such installation is handled under
the exception process in section 7.
3. Automatic Updates as the Primary Control
Automatic updating is the default and primary patch mechanism for all endpoint software.
- Vendor automatic updates must be enabled for all Tier 1 and Tier 2 software, on the vendor’s
stable release channel. Personnel must not disable them.
- Where an operating system app store or package manager can deliver the software, it is installed
through that channel so that updates are centrally applied rather than managed per application.
- Browsers are the highest-priority case. Browser updates frequently require a relaunch to take
effect, so personnel must fully restart their browsers at least weekly, and immediately when a
pending-update indicator is shown, so that downloaded patches are actually applied.
- Because Optizio does not currently operate centralised device management, enforcement is by
configuration standard rather than by technical policy push. Compliance is confirmed at the
verification review defined in section 6, which is the compensating control for the absence of
centralised enforcement.
4. Vulnerability Monitoring
- Vendor security advisories, release notes, and update channels are monitored for all Tier 1
software.
- The CISA Known Exploited Vulnerabilities (KEV) catalogue is monitored for entries affecting
software in use at Optizio. A KEV listing escalates remediation to the highest priority
regardless of the vendor’s own severity rating.
- Where a vendor publishes a CVSS score, it is used to assign the remediation timeline in
section 5. Where none is published, severity is assessed internally based on exploitability and
exposure.
Timelines are measured from the vendor’s publication of a fix.
| Severity |
Target |
| Actively exploited (CISA KEV listed, or public working exploit) |
Immediately, and no later than 72 hours |
| Critical (CVSS 9.0–10.0) |
Within 72 hours |
| High (CVSS 7.0–8.9) |
Within 7 days |
| Medium (CVSS 4.0–6.9) |
Within 30 days |
| Low (CVSS 0.1–3.9) |
Within 30 days, or the next routine update cycle |
| Tier 2 bulk update cycle |
Monthly |
Where a patch cannot be applied within the target window, the software is removed, or its use is
suspended, until a fix is available. If neither is possible, an exception is raised under
section 7.
6. Verification and Evidence
- Each endpoint’s third-party software inventory is reviewed at least monthly, and immediately
following any emergency patch, to confirm that updates have in fact been applied.
- The review is performed using the endpoint inventory script maintained in Optizio’s internal
policy repository, which reports installed versions, pending updates, the status of each Tier 1
category, and the presence of any prohibited software.
- The script output is retained as the evidence record for a minimum of 12 months, together
with the reviewer’s name, the review date, and any remediation actions taken.
- Evidence records are stored in Optizio’s internal document store. They must not be committed
to this repository or to any other public location, because they disclose the exact software
versions in use and would assist an attacker in reconnaissance.
- Any endpoint found running unsupported or unpatched Tier 1 software is remediated before it is
next used for work involving customer data or production systems.
7. Exceptions
- Any deviation from this policy, including retention of an unpatched or end-of-life application
for compatibility reasons, requires documented approval from management before the deviation
begins.
- Each exception must record the business justification, the compensating controls applied, the
accepted risk, the responsible owner, and an expiry date.
- Open exceptions are reviewed at least quarterly and are closed as soon as the underlying need
ends.
8. Endpoint Separation from Production
Endpoint patching is one layer of defence rather than the primary protection for customer data.
- No customer data is stored on endpoint systems. Optizio applications run on Shopify and
Cloudflare infrastructure, and customer data resides in managed cloud services.
- Access to production systems requires multi-factor authentication and is granted on a
least-privilege basis, as set out in the Information Security Policy.
- Compromise of an endpoint therefore does not by itself grant access to production data.
9. Roles and Responsibilities
- Management: Approves this policy and any exceptions, and ensures the monthly review is
carried out.
- IT/Admin: Runs the inventory review, applies or verifies patches, monitors advisories and
the KEV catalogue, and retains evidence records.
- All personnel: Keep automatic updates enabled, restart applications when updates are
pending, install software only from approved sources, and report any software that cannot be
updated.
10. Policy Review
This policy is reviewed annually, or upon significant changes to the endpoint estate, business
operations, or the threat landscape. Adoption of centralised device management would trigger a
review of sections 3 and 6.
Updates are communicated to all relevant staff and stakeholders.