Skip to main content

Out-of-Band Security Patch

Use this playbook to respond to a critical security vulnerability that requires patching outside the normal schedule.

Procedure

  1. Triage and scope the vulnerability.

    • Confirm severity and exploitability using vulnerability advisories and your Vulnerability Management module.
    • Identify affected packages, versions, and hosts via CMDB and patch/vulnerability data.
    • Decide which environments and systems must be patched urgently (for example, internet‑facing services).
  2. Plan the emergency release.

    • Create an emergency baseline focusing on patches that address the critical vulnerability and required dependencies.
    • Define clear rollback criteria and testing steps.
    • Prepare a communication plan for affected teams and leadership.
  3. Handle approvals and change records.

    • Use emergency change procedures where available.
    • Obtain rapid approvals from security and operations leadership.
    • Document risk, impact, and mitigation steps in the change record.
  4. Execute and monitor.

    • Contact Сloudaware to request the emergency security patch (on a small canary wave if time allows, then request rollout on a broader scope).
    • Monitor system and application health, as well as security monitoring for signs of active exploitation.
    • Update stakeholders frequently on progress.
  5. Verify and close.

    • Confirm that patched systems no longer show the vulnerability in scans.
    • Review logs and metrics for residual issues.
    • Close emergency changes and update standard patch schedules or baselines if needed.