
Appendix L: Gap Analysis Examples ◾ 329
NERC CIP-007-1 System Security Management
R 3 Security Patch Management A change management process to track, evaluate, and approve all software patches
must be implemented.
R 3.1
Document Patch Assessment Are procedures in place to document
the assessment of security patches
and upgrades?
Y ITS-209 Standards for Security Patch
Management
R 3.2
Exceptions Are procedures in place to identify
and document all security patches
that have not been installed?
Y ITS-209 Standards for Security Patch
Management