Skip to content

Configure patching policy

Welcome to the Ostorlab tutorial on configuring the patching policy for your organization. The Patching Policy establishes a schedule for addressing vulnerabilities to efficiently manage risk. Utilizing deadlines determined by the risk rating and priority of each vulnerability, it provides guidance for metrics tracking and facilitates remediation efforts to meet established SLOs.

Configuring Patching Policy Based on Risk Rating.

Navigate to the Policies section in the side menu.

Navigate to Policies

Click Policies

Then click on Patching.

Click Patching

You can configure the SLO period for each risk rating: Critical, High, Medium, Low, and Hardening.

Configure SLO Period

For example, let's set a 3-day period for critical vulnerabilities.

Set 3 Days for Critical

And 5 days for high ones.

Set 5 Days for High

Then, 15-day for medium vulnz.

Set 15 Days for Medium

You can enable or disable an SLO for a specific risk rating by toggling this button.

Toggle SLO

After completing your configuration, don't forget to click on the SAVE button to apply your patching policy settings.

Click Save

When editing the current configuration, you can click on the Reset button to restore the configuration if you are unsure about your changes.

Click Reset

Configuring Patching Policy Based on Ticket Priority.

Go back to the menu.

Go Back to Menu

Select the option labeled "Priority".

Click Priority

You can configure the SLO period for each priority: P0, P1, P2, and P3.

Configure SLO Priority

For example, let's set a maximum of 1 day for tickets with priority P0.

Set 1 Day for P0

And a maximum of 3 days for tickets with P1.

Set 3 Days for P1

You can also enable or disable an SLO for a specific priority.

Toggle SLO Priority Toggle SLO Priority

Finally, click on Save to apply your changes.

Click Save Priority

This guide covered the steps to configure the patching policy. By following these instructions, you can set up your patching policy with ease.