patching operation
A coordinated, end-to-end execution activity — encompassing vulnerability identification, patch acquisition, testing, scheduling, deployment, and verification — carried out against a defined set of systems or assets within a managed change-management framework. It is distinguished from *patch management* (the overarching program or policy) by its operational, time-bounded character: a patching operation is the discrete act of *doing* the work, not the governance structure that governs it. In practice, the field uses it to describe the full workflow that must be completed in order to close a known vulnerability window, covering everything from urgency review through post-deployment confirmation, and it appears in standards guidance — notably CISA's recommended practice for control-system patch management — as a structured flow with discrete decision points such as emergency versus routine cadences, change-control approvals, and rollback options.