Glossary
The words this job uses
Coordination, vulnerability-management and regulatory terms, defined the way an operations team actually uses them.
26 terms
A
Air gap
A network with no internet connectivity. Everything that enters passes through a controlled transfer, so anything that calls out simply will not work.
Audit trail
A chronological record of the actions performed during a change, retained to support investigation and problem resolution during and after it.
B
Blast radius
Everything affected when one system goes down — including the systems that depend on it and did not know they did. What sets a window's real risk.
Business Impact Analysis
BIAA mapping of what happens to the business when a system is unavailable: who is affected, how fast, and at what cost. The basis for non-technical ranking.
C
Change Advisory Board
CABThe forum that approves production changes. For patching, the body that decides whether a class of window may go ahead and who carries it.
Change freeze
A defined period in which production changes are not permitted — quarter end, year end, a business event — except for approved emergency changes.
Cumulative update
LCU — latest cumulative updateAn update containing every fix that preceded it. Installing the latest one also closes everything that was missed before it.
CVE
Common Vulnerabilities and ExposuresA public unique identifier for one security vulnerability, in the form CVE-YYYY-NNNN. The shared language that lets tools talk about the same flaw.
CVSS
Common Vulnerability Scoring SystemAn open standard scoring the technical severity of a vulnerability from 0 to 10. It measures the flaw — not the risk to the system it happens to sit on.
D
E
Emergency change
A change that cannot wait for the normal process. §97 of Directive 364 requires defined procedures for assessing and approving it, and a named approver.
End of life / end of support
EOL / EOSThe date from which a product no longer receives security updates. After it, a new vulnerability will not be closed by a patch — it needs another decision.
EPSS
Exploit Prediction Scoring SystemA model estimating the probability that a vulnerability will be exploited in the near term. It complements a severity score rather than replacing it.
K
M
N
P
Patch cadence
How often a system gets a planned maintenance window. Usually derived from how exposed the host is and how critical the system on it is.
Patch coordination
The work between finding a vulnerability and installing the fix: grouping, ranking, proposing a window, getting approval, and recording what happened.
Patch group
The set of vulnerabilities one patch closes, together with every host it applies to. The unit a maintenance window can actually be booked for.
Patch Tuesday
The second Tuesday of each month, when Microsoft publishes its monthly security rollup. The rhythm most Windows estates plan their year around.
R
Remediation SLA
The maximum time defined between finding a vulnerability and fixing it, by severity and asset criticality. A target you can be measured against.
Rollback plan
What to do when the update fails: how to get back to the previous state, how long that takes, and who decides it is time to stop and revert.
RTO and RPO
Recovery Time Objective / Recovery Point ObjectiveHow long a system may be down, and how much data may be lost. The two objectives that decide how long a maintenance window you can afford.
S
W
Window collision
Two windows overlapping in time on systems that depend on each other. Each was properly approved, and neither approver knew about the other.
WSUS target group
The group a host belongs to on the internal Windows update server, which decides which approved updates it receives and in which wave.