{"id":24564,"date":"2022-09-02T16:48:15","date_gmt":"2022-09-02T16:48:15","guid":{"rendered":"https:\/\/one.sightlinemg.com\/federaltimes\/uncategorized\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/"},"modified":"2026-08-08T05:00:25","modified_gmt":"2026-08-08T05:00:25","slug":"five-best-practices-for-risk-based-patch-management-in-government","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/","title":{"rendered":"Five best practices for risk-based patch management in government"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Amid staffing shortages and limited budgets, organizations and government agencies are struggling to strike a balance between enhancing productivity and ensuring proper cyber hygiene, making it difficult to effectively defend against cyber threats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.axios.com\/2022\/08\/24\/twitter-security-alarm-mudge-zatko-whistleblower\">Twitter is just the latest example of this<\/a> \u2013 the whistleblower complaint filed by the company\u2019s former security boss demonstrates that the company may prioritize feature functionality over strong cybersecurity (i.e., measuring key risk indicators, delivering secure code, maintaining secure devices).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Meanwhile, attacks are increasingly overwhelming in boldness, sophistication and volume. Even well-staffed, well-funded IT and security teams are effectively grasping at straws \u2013 unless they have a risk-based patch management solution in place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">RBPM means narrowing down active threat mitigation efforts and patching to the highest priority threats. These priorities are determined based on both external threat context and the internal security environment of an individual federal organization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Patching is not nearly as simple as it sounds, and government security teams often don\u2019t get around to it amidst other pressing demands. In a recent survey by Ivanti, <a href=\"https:\/\/www.ivanti.com\/company\/press-releases\/2021\/71-of-it-security-pros-find-patching-to-be-overly-complex-and-time-consuming-ivanti-study-confirms\">71% of IT and security professionals reported that they found patching to be both time-consuming and complicated<\/a>. An RBPM program \u2013 especially one enhanced by certain best practices \u2013 can reduce risk without increasing workload.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here are five of those best practices:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Start with asset discovery<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can\u2019t protect what you can\u2019t see. A team can be working around the clock to create patches for specific threats and specific assets and still miss the boat if they\u2019re not aware what they actually <i>need <\/i>to be patching. That\u2019s wasted effort \u2013 and a huge point of vulnerability. That\u2019s why any RBPM program must start with asset discovery.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What assets are on your network? Which end user profiles use those assets? In the pre-pandemic era, asset management was more straightforward: what and who are behind our perimeter, in our office? In the modern everywhere workplace, assets and end users are dispersed. That calls for a modern approach to asset management \u2013 one that can discover, map, secure, and service any asset, anywhere \u2013 even when they\u2019re offline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once you know what you need to protect, you can start protecting it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Get everyone on the same page<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Despite best intentions, IT operations and security teams are often working in conflict \u2013 simply by the nature of their roles and areas of focus. RBPM creates a bridge between these organizations, demanding that external threats and internal security environments are considered in tandem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In order for these organizations to work together, they must all have the same information as well as mutually acknowledged risk analysis. When everyone is on the same page, security can stop treating <i>everything <\/i>as an urgent risk and can prioritize the most critical vulnerabilities. IT operations can stop feeling like they\u2019re drinking from a firehose and make time for the right patches at the right time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Leverage an SLA for patch management<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You already know that security and IT operations need to work together to create and execute an effective RBPM solution. Of course, it\u2019s one thing to <i>know <\/i>they need to work together \u2013 and quite another to ensure they are enabled, empowered, and motivated to do so.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A service-level agreement (SLA) for patch management between the security and IT operations teams can eliminate back-and-forth and standardize processes for patch management. It should lay out department-level goals and enterprise-wide goals for patch management, establish best practices and processes, and identify maintenance windows that are acceptable for all parties.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Leverage pilot groups for patching<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Done right, a RBPM strategy allows IT operations and security teams to work <i>fast<\/i>, identifying critical vulnerabilities in real-time and working to patch them as soon as possible. Speed is of utmost importance \u2013 so long as it doesn\u2019t cause excess collateral damage. A hasty patch runs the risk of crashing mission-critical software or creating other unwanted problems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The solution: leverage pilot groups featuring key stakeholders who can test vulnerability patches in a live environment prior to full rollout. Optimally, these stakeholders would reflect the device configurations and user roles that will be impacted by a piloted patch. Live environments provide a more accurate assessment than any lab can replicate, and we\u2019re not at the point of being able to perfectly identify potential downstream impacts of patches. If the pilot group identifies a catastrophic error, it can be remedied with minimal enterprise impact. It\u2019s important to predetermine and pretrain pilot groups so this process doesn\u2019t substantially inhibit patch progress.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><b>Embrace automation<\/b><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The point of RBPM is to mitigate vulnerabilities efficiently and effectively while alleviating the burden on your staff \u2013 particularly as IT faces an unprecedented worker shortage. However, it\u2019s still a heavy lift when done manually. Automation can dramatically accelerate the speed and accuracy of a RBPM program, collecting, contextualizing, and prioritizing vulnerabilities around the clock, far faster than even the most talented team could manage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Automation can also segment a patch rollout to test for efficacy and downstream impacts as well, supplementing the work of the pilot groups mentioned above.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The ability to automatically identify, prioritize, and even address vulnerabilities without excess manual intervention is a critical advantage in today\u2019s cybersecurity landscape. That\u2019s why it\u2019s so concerning that, according to Twitter\u2019s former head of security, around 30% of the company\u2019s laptops had automatic software updates blocked. This, along with other security failures, resulted in Twitter suffering more than 50 incidents in the past year.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a RBPM solution is dependent on the nuances of a particular organization or federal agency, there isn\u2019t a one-size-fits-all RBPM strategy. These best practices, however, can inform any RBPM program \u2013 and make all the difference in the world.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><i>Srinivas Mukkamala is Senior Vice President, Security Products at Ivanti. Prior to Ivanti he was a Co-Founder and CEO of RiskSense, a risk-based vulnerability management company, and was part of a think tank that collaborated with the U.S. Department of Defense and U.S. Intelligence Community on applying these concepts to cybersecurity problems.<\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>RBPM can focus active cyber mitigation efforts on the highest priority threats.<\/p>\n","protected":false},"author":7,"featured_media":53669,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":14,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[63,12,31,15,14,22],"tags":[],"coauthors":[5819],"class_list":["post-24564","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud","category-govcon","category-home","category-management","category-it-networks","category-thought-leadership"],"acf":{"subheadline":"","legacy_arc_id":"PBNUKTBPEVHELDRNX73EIAH76I","arc_canonical_url":"\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Five best practices for risk-based patch management in government - Federal Times<\/title>\n<meta name=\"description\" content=\"RBPM can focus active cyber mitigation efforts on the highest priority threats.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Five best practices for risk-based patch management in government\" \/>\n<meta property=\"og:description\" content=\"RBPM can focus active cyber mitigation efforts on the highest priority threats.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/\" \/>\n<meta property=\"og:site_name\" content=\"Federal Times\" \/>\n<meta property=\"article:published_time\" content=\"2022-09-02T16:48:15+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T05:00:25+00:00\" \/>\n<meta name=\"author\" content=\"Srinivas Mukkamala\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Srinivas Mukkamala\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"Five best practices for risk-based patch management in government\",\n\t            \"datePublished\": \"2022-09-02T16:48:15+00:00\",\n\t            \"dateModified\": \"2026-08-08T05:00:25+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/\"\n\t            },\n\t            \"wordCount\": 1010,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-903456766.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Cloud\",\n\t                \"GovCon\",\n\t                \"Home\",\n\t                \"Inside the Agencies\",\n\t                \"IT &amp; Networks\",\n\t                \"Thought Leadership\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/\",\n\t            \"name\": \"Five best practices for risk-based patch management in government - Federal Times\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-903456766.jpg.jpg\",\n\t            \"datePublished\": \"2022-09-02T16:48:15+00:00\",\n\t            \"dateModified\": \"2026-08-08T05:00:25+00:00\",\n\t            \"description\": \"RBPM can focus active cyber mitigation efforts on the highest priority threats.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-903456766.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-903456766.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/2022\\\/09\\\/02\\\/five-best-practices-for-risk-based-patch-management-in-government\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"IT &amp; Networks\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/it-networks\\\/\",\n\t                    \"ad_zone\": \"it-networks\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"Five best practices for risk-based patch management in government\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"name\": \"Federal Times\",\n\t            \"description\": \"Federal Times\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#organization\",\n\t            \"name\": \"Federal Times\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"caption\": \"Federal Times\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/federaltimes\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Five best practices for risk-based patch management in government - Federal Times","description":"RBPM can focus active cyber mitigation efforts on the highest priority threats.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Five best practices for risk-based patch management in government","og_description":"RBPM can focus active cyber mitigation efforts on the highest priority threats.","og_url":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/","og_site_name":"Federal Times","article_published_time":"2022-09-02T16:48:15+00:00","article_modified_time":"2026-08-08T05:00:25+00:00","author":"Srinivas Mukkamala","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Srinivas Mukkamala","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"Five best practices for risk-based patch management in government","datePublished":"2022-09-02T16:48:15+00:00","dateModified":"2026-08-08T05:00:25+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/"},"wordCount":1010,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-903456766.jpg.jpg","articleSection":["Cloud","GovCon","Home","Inside the Agencies","IT &amp; Networks","Thought Leadership"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/","url":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/","name":"Five best practices for risk-based patch management in government - Federal Times","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-903456766.jpg.jpg","datePublished":"2022-09-02T16:48:15+00:00","dateModified":"2026-08-08T05:00:25+00:00","description":"RBPM can focus active cyber mitigation efforts on the highest priority threats.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-903456766.jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-903456766.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/09\/02\/five-best-practices-for-risk-based-patch-management-in-government\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/federaltimes\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"IT &amp; Networks","item":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/","ad_zone":"it-networks"},{"@type":"ListItem","position":3,"name":"Five best practices for risk-based patch management in government"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#website","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","name":"Federal Times","description":"Federal Times","publisher":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/federaltimes\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#organization","name":"Federal Times","url":"https:\/\/one.sightlinemg.com\/federaltimes\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","caption":"Federal Times"},"image":{"@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/federaltimes\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/federaltimes\/author\/migration\/"}]}},"jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Federal Times","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/federaltimes","push-errors":false,"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-903456766.jpg.jpg","_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/24564","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/comments?post=24564"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/24564\/revisions"}],"predecessor-version":[{"id":24566,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/24564\/revisions\/24566"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/media?parent=24564"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/categories?post=24564"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/tags?post=24564"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/coauthors?post=24564"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}