Author: DTNK Redaktion
Published:

A dependable process starts with an inventory
Record products, versions, owners, business dependencies and whether systems are internet-facing. Support status must be checked for each product and version because vendor lifecycles differ. Group comparable systems into maintenance cohorts, while keeping a separate path for rarely connected devices and specialist applications.
Prioritise according to risk and business impact
Confirm whether the exact deployed version is affected, whether exploitation has been observed, how exposed the system is and which business process depends on it. The CISA Known Exploited Vulnerabilities Catalog is a useful prioritisation signal, but deadlines for US federal agencies are not transferred to German businesses. Vendor information and your own exposure assessment remain necessary.
Use a representative test group and a rollback plan
The BSI module on patch and change management calls for planned, approved and documented changes, suitable testing and rollback options. Start with representative devices or systems and define stop criteria, decision owners and the practical route back to a usable state.
Separate routine maintenance from emergency patching
Plan routine updates within agreed maintenance windows and tell affected teams what to expect. For urgent security updates, use a predefined accelerated path. NIST recommends retaining a small test group for emergency patching where the situation allows. Temporary mitigations need a documented owner, review date and controlled removal once a permanent remedy is available.
Verify installation and usability
A deployment message is not complete evidence. Confirm the intended version on relevant systems, test important applications and follow up devices that were offline. Record each exception with its reason, owner, compensating measure and next review date.
Use a practical seven-point review
Inventory systems and owners; monitor vendor sources; assess exposure and impact; define pilot, approval and stop criteria; document routine and emergency paths; verify installation and important functions; and track exceptions until they are resolved or formally reassessed. Related DTNK service areas include workplace management, server infrastructure, monitoring and IT security.
Sources and editorial basis
Sources checked: 11 October 2026. Primary references: BSI OPS.1.1.3, NIST SP 800-40 Rev. 4, the CISA KEV Catalog and the Microsoft Lifecycle FAQ. Product status and vendor deadlines can change and should be checked for the specific version in use.
