# 5. Security Update Management

The goal of this control is to ensure that devices remain up-to-date to mitigate the latest threats.

This control expects organisations to ensure all software on all devices are:

* Licensed and supported.
* Removed from devices when they become unsupported or removed from scope.
* Enabled automatic updates where possible.
* Updated within 14 days of a patch release in cases where:
  * The update fixes vulnerabilities considered 'critical' or 'high risk'.
  * The update addresses vulnerabilities with a CVSS v3 score of 7 or above.
  * There are no details of the level of vulnerabilities the update fixes provided by the vendor.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://manual.harpe.io/start/cyber-essentials-wiki/controls/5.-security-update-management.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
