Patches are software updates that fix bugs, vulnerabilities, or improve performance or functionality. Patches are important for maintaining the security and reliability of an IACS environment, but they also pose some challenges and risks. Applying patches in an IACS environment is not as simple as in an IT environment, because patches may affect the availability, integrity, or safety of the IACS. Therefore, patches should not be applied blindly or automatically, but based on the organization’s risk assessment. The risk assessment should consider the following factors: 1
The severity and likelihood of the vulnerability that the patch addresses
The impact of the patch on the IACS functionality and performance
The compatibility of the patch with the IACS components and configuration
The availability of a backup or recovery plan in case the patch fails or causes problems
The testing and validation of the patch before applying it to the production system
The communication and coordination with the stakeholders involved in the patching process
The documentation and auditing of the patching activities and results References: ISA TR62443-2-3 - Security for industrial automation and control systems, Part 2-3: Patch management in the IACS environment