Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · Industrial cybersecurity

Patch management

Also known as: security patch management

German: Patch-Management

In industrial cybersecurity, patch management is the controlled identification, assessment, testing, deployment and verification of software patches for control systems and their components, balancing security risk against the risk of changing a running production system.

  • Cybersecurity
  • Compliance

In one sentence

Patch management identifies, assesses, tests, deploys and verifies software patches for industrial systems without compromising safety or production.

Example

A vulnerability is published for the HMI operating system of a packaging line; the operator checks the supplier’s compatibility statement, tests the patch on a spare panel, installs it during a planned stop and verifies the safety functions.

How it applies

  • Cybersecurity: The IEC 62443 series includes guidance on patch management for industrial automation and control systems, addressing both asset owners and product suppliers. Patching in OT is often delayed by availability and qualification constraints, so compensating measures need to be documented.
  • Machine safety: A patch to software that can affect safety functions is a change under change control. Assess whether safety functions must be re-verified before returning to production.
  • Compliance: The CRA requires manufacturers to address vulnerabilities through security updates during the support period. Operators still decide when and how to install them.
  • Technical documentation: Suppliers should document which patches are approved for which versions, how to install and verify them and how to roll back; see rollback capability.

Patch management vs. update capability

Update capability is the product's and organization's ability to deliver, verify and reverse updates. Patch management is the ongoing process that uses this capability for specific patches. Without update capability, patch management is reduced to workarounds.

By knowledge.aitechdoc.world · Published September 25, 2026 · Last reviewed

Source: IEC 62443 series, Security for industrial automation and control systems

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!