home/dictionary/system upgrade

system upgrade

nounverified·updated Aug 30, 2026

A planned, authorized lifecycle event in which one or more components of an operational information system — software, firmware, or hardware — are replaced or advanced to a newer version, typically involving a service interruption or maintenance window. It is distinguished from a routine patch or hotfix by its broader scope: a system upgrade commonly replaces a major version, introduces new functionality, or transitions the platform itself, rather than simply remediating a discrete vulnerability. In security and compliance frameworks it appears alongside scheduled maintenance as a category of anticipated downtime that must be governed by change-management controls — including authorization, scheduling, testing, and documented rollback plans — so that the upgrade event does not itself introduce new risk or violate availability commitments. The phrase is compositional (upgrade of a system) rather than a specialized term of art with a fixed regulatory definition, and its meaning is understood directly from its component words across NIST, CMMC, and related authority documents.

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A planned, authorized lifecycle event in which one or more components of an operational information system — software, firmware, or hardware — are replaced or advanced to a newer version, typically involving a service interruption or maintenance window. It is distinguished from a routine patch or hotfix by its broader scope: a system upgrade commonly replaces a major version, introduces new functionality, or transitions the platform itself, rather than simply remediating a discrete vulnerability. In security and compliance frameworks it appears alongside scheduled maintenance as a category of anticipated downtime that must be governed by change-management controls — including authorization, scheduling, testing, and documented rollback plans — so that the upgrade event does not itself introduce new risk or violate availability commitments. The phrase is compositional (upgrade of a system) rather than a specialized term of art with a fixed regulatory definition, and its meaning is understood directly from its component words across NIST, CMMC, and related authority documents.
DR-088 backfill from the noun definition column