patching operation
A coordinated, end-to-end execution activity — encompassing vulnerability identification, patch acquisition, testing, scheduling, deployment, and verification — carried out against a defined set of systems or assets within a managed change-management framework. It is distinguished from *patch management* (the overarching program or policy) by its operational, time-bounded character: a patching operation is the discrete act of *doing* the work, not the governance structure that governs it. In practice, the field uses it to describe the full workflow that must be completed in order to close a known vulnerability window, covering everything from urgency review through post-deployment confirmation, and it appears in standards guidance — notably CISA's recommended practice for control-system patch management — as a structured flow with discrete decision points such as emergency versus routine cadences, change-control approvals, and rollback options.
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- patching operations
- possessive
- patching operation's
- pluralpossessive
- patching operations'