Patch Management Policy
POLICY #: CR 26-4
DATE OF BOARD OF TRUSTEES APPROVAL: 9/28/2026
RESOLUTION #: 26-4
Purpose:
The purpose of this policy is to enforce patch requirements for College-owned or managed Information Technology (IT) Resources.
Scope:
This policy and all policies referenced herein, shall apply to all members of the College community, including employees, students, alumni, authorized guests, and independent vendors who use, access, or otherwise employ, locally or remotely, the College’s IT Resources, whether individually controlled, shared, stand-alone, or networked.
Definitions:
- IT Resources: Includes computing, networking, communications, application, and telecommunications systems and infrastructure; hardware and software; data and databases; personnel; procedures; physical facilities; cloud-based and Software as a Service (SaaS) vendors; and other related materials, services, and resources.
- Patch: A software update that modifies or replaces code within an existing software application or executable program. Patches are typically used to address specific issues or make incremental changes between major software releases. Patches may include, but are not limited to:
- Updating or improving software functionality.
- Correcting software bugs or defects.
- Installing or updating device drivers.
- Implementing or strengthening security controls.
- Addressing newly identified security vulnerabilities.
- Resolving software stability, reliability, or performance issues.
- Patch Management Cycle: A component of IT lifecycle management that establishes a systematic process for identifying, evaluating, prioritizing, testing, scheduling, deploying, and verifying patches for College IT Resources.
Patch Management Cycle:
The College shall maintain a systematic patch management cycle to ensure that IT Resources are routinely assessed, updated, and protected against known security vulnerabilities. The Patch Management Cycle shall include the following tenets:
- All College IT Resources must be included in an established patch management cycle.
- IT is responsible for managing and maintaining patch management cycles unless otherwise specified.
- When an approved exclusion or exception is granted, the owner or manager of the affected IT Resource is responsible for ensuring required patches are applied or for notifying IT when assistance is needed.
- All required security patches must be deployed to College-owned or College-managed IT Resources when a vulnerability is identified and determined to require remediation in accordance with the Vulnerability Management Policy.