nerdexam
Isaca

CRISC · Question #285

An organizational policy requires critical security patches to be deployed in production within three weeks of patch availability. Which of the following is the BEST metric to verify adherence to the

The correct answer is A. Maximum time gap between patch availability and deployment. The best metric to verify adherence to a policy requiring critical security patches within three weeks is the maximum time gap between patch availability and deployment, as it directly identifies any instances exceeding the prescribed limit.

Submitted by ngozi_ng· Apr 18, 2026Governance

Question

An organizational policy requires critical security patches to be deployed in production within three weeks of patch availability. Which of the following is the BEST metric to verify adherence to the policy?

Options

  • AMaximum time gap between patch availability and deployment
  • BPercentage of critical patches deployed within three weeks
  • CMinimum time gap between patch availability and deployment
  • DNumber of critical patches deployed within three weeks

How the community answered

(40 responses)
  • A
    73% (29)
  • B
    3% (1)
  • C
    18% (7)
  • D
    8% (3)

Why each option

The best metric to verify adherence to a policy requiring critical security patches within three weeks is the maximum time gap between patch availability and deployment, as it directly identifies any instances exceeding the prescribed limit.

AMaximum time gap between patch availability and deploymentCorrect

The policy sets a maximum allowable deployment time of three weeks. By tracking the maximum time gap, an organization can identify any single instance where the policy was violated, ensuring that the critical deadline for all patches is met, not just a percentage.

BPercentage of critical patches deployed within three weeks

Percentage of critical patches deployed within three weeks could mask individual failures; if 99% are deployed within time, but one critical patch takes four weeks, the policy is still violated for that specific patch.

CMinimum time gap between patch availability and deployment

The minimum time gap is irrelevant to verifying adherence to a maximum deployment timeframe.

DNumber of critical patches deployed within three weeks

The number of critical patches deployed within three weeks doesn't indicate if all relevant patches met the three-week deadline or if any individual patch exceeded it.

Concept tested: Policy adherence metrics (patch management)

Source: https://csrc.nist.gov/publications/detail/sp/800-40/rev-3/final

Topics

#Policy adherence#Performance metrics#Compliance monitoring#Vulnerability management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice