← Field notesThe control explained · 28 Sep 2026

Control 2405: patching has a clock, and you set it.

Def Stan 05-138 asks you to patch within industry best-practice timelines. It never says what those are. That part is yours to write.

Control 2405, patch management, applies at Cyber Risk Profile Levels 1, 2 and 3 and sits alongside control 2402, vulnerability management. Verbatim, it asks the Supplier to:

  1. Develop and maintain an appropriately robust patch management programme to address known vulnerabilities on its network within industry best-practice timelines.
  2. Take appropriate steps to identify, assess, test and implement patches for endpoints, network devices and software.
  3. Have appropriate processes in place to address out-of-band emergency patching and/or mitigating actions.

Three things worth noticing.

First, it names network devices. Endpoint patching is usually automated and reported. Firewalls, switches and remote access appliances are often patched by hand, by one person, when they have time. That is where gaps tend to open, and it is where a large share of this month's exploited vulnerabilities sit.

Second, because the standard does not define best practice, your policy should name the timelines and the source you took them from, so an assessor can see why you chose them.

Third, emergency patching is its own requirement. A process that only runs on the monthly cycle does not meet it. Write down what happens when a vendor you run is added to the KEV list on a Tuesday afternoon. Who decides, how fast, and what you do if the patch cannot go in yet.

Source: Def Stan 05-138 Issue 4, control 2405 Patch management, read at source. Levels from the control table (L1, L2, L3).

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes