Skip to main content

Data Governance

Patch Management generates operational data, including status history and compliance metrics. This data is currently available in analytics dashboards, and can be treated as part of your broader governance and retention strategy.

Use this guide to review considerations for retaining patch records, protecting sensitive data, and maintaining audit evidence.

Retention and Privacy

  • Decide how long you need to retain history/metrics and snapshots.
  • Ensure retention policies meet regulatory and audit requirements.
  • Consider whether patch data contains personal or sensitive information and apply appropriate protections.

Evidence and Audit Trails

  • Keep records of patch releases linked to changes, incidents, and vulnerabilities.
  • Use patch summary reports, CMDB list views and dashboards such as the Historical patching dashboard for audits to show which systems were patched, when, and how.
  • Make sure patch activity is included in your wider security and operational audit programs.