Patch Applications (E8.2)
Patch Operating Systems (E8.3)
Regulatory basis: ISO 27001 §12.6.1 names network-border access controls as acceptable compensating controls when patches cannot be deployed in time. The ASD ISM similarly accepts vendor mitigations as alternatives to direct patching for internet-facing systems.