Aligning ACSC Essential Eight Patch Management with Azure Update Manager

Aligning ACSC Essential Eight Patch Management with Azure Update Manager

For hybrid Azure estates operated by Western Australian Government agencies and financial services organisations, patch management is one of the most persistent sources of audit friction. The Australian Cyber Security Centre places both application patching and operating system patching among the eight mitigation strategies of the Essential Eight, and each carries defined timeframes that assessors expect to see met and evidenced. The recurring difficulty is not applying patches at all, but demonstrating consistently that they were applied within the required windows across a mixed fleet of Azure virtual machines, on-premises servers, and workloads elsewhere.

Azure Update Manager offers a Microsoft-native path to close that evidence gap. It provides assessment, scheduled remediation, and compliance reporting for both Windows and Linux systems, and it extends to servers outside Azure through Azure Arc. This article explains how the service maps to Essential Eight patch management expectations, and how technical and governance teams can use it to produce the auditable cadence their maturity targets demand.

Understanding the Essential Eight patch management expectations

The Essential Eight Maturity Model separates patching into two strategies, one for applications and one for operating systems, and applies graduated timeframes according to exposure. Patches for internet-facing services are expected within 48 hours where a working exploit exists, and otherwise within two weeks. Patches for other applications and for operating systems on workstations, servers, and network devices are generally expected within one month, with tighter regular scanning cadences at higher maturity levels. These timeframes are not aspirational statements; they are the yardstick an assessor uses to determine which maturity level an organisation has genuinely achieved.

The model also expects regular vulnerability scanning to identify missing patches, ranging from daily scanning of internet-facing services to fortnightly or weekly scanning of other systems depending on the level pursued. This means that reaching a target maturity level is as much about the rhythm of detection and reporting as it is about the act of patching. Organisations frequently discover that their genuine obstacle is producing defensible records showing when a vulnerability was detected, when the patch was applied, and how the gap between the two compared against the applicable window.

How Azure Update Manager supports auditable patch cadence

Azure Update Manager is a native Azure service that assesses machines for missing updates and applies them on schedules the organisation defines. It supports on-demand assessment and remediation as well as recurring maintenance windows, which allows teams to align patch cycles with the two week and one month expectations set out in the maturity model. Because assessment results and deployment outcomes are retained within the platform, the service becomes a source of evidence rather than a task that must be reconstructed after the fact.

The compliance view is where the alignment becomes tangible. Update Manager reports on the patch status of each machine, distinguishes between assessment and installation activity, and records the outcome of each scheduled run. When combined with Azure Policy, organisations can enforce that machines carry periodic assessment and are enrolled in maintenance configurations, which converts a manual discipline into a governed default. This reduces the risk of individual servers drifting outside the required cadence without anyone noticing until an audit.

Evidencing maturity across hybrid and on-premises estates

Few agencies in Western Australia run entirely in Azure. Legacy application servers, domain infrastructure, and sector-specific systems often remain on-premises, and it is precisely these systems that create the largest evidence gaps. Azure Update Manager addresses this through Azure Arc, which projects on-premises and other cloud servers into Azure so they can be assessed and patched under the same policies and reporting as native virtual machines. This gives a single, consistent view of patch compliance across the whole estate rather than fragmented records held in separate tools.

For financial services organisations subject to regulatory scrutiny and for government agencies reporting against the Essential Eight, that consolidation matters. A unified compliance surface allows a team to answer the assessor's core questions with exported data rather than anecdote, showing which systems were assessed, which patches were pending, and when remediation occurred. It also supports internal governance, because the same dashboards that satisfy an external auditor help operations teams triage overdue systems before a deadline is breached.

Practical steps for Western Australian Government and financial services

A pragmatic starting point is to inventory every server and workstation category against its applicable timeframe, distinguishing internet-facing services from internal systems. Once that mapping exists, organisations can define maintenance configurations in Azure Update Manager that reflect the two week window for exposed services and the one month window for the broader fleet, then onboard non-Azure machines through Arc so that nothing sits outside the reporting boundary. Enforcing enrolment through Azure Policy prevents new or rebuilt machines from silently escaping the regime.

Beyond configuration, teams should establish a regular review rhythm that mirrors the scanning cadence their maturity target requires, and retain exported compliance reports as durable evidence. It is worth remembering that Update Manager addresses operating system and supported application patching, so applications outside its scope still need a documented process to satisfy the application patching strategy in full. Treating the service as the backbone of patch governance, rather than the entirety of it, keeps the compliance narrative honest and complete when the assessment arrives.

References

Coffee's on us!

Our 💟 for great ☕is second only to our dedication to delivering strategies that drive your business forward.

Let’s discuss how our solutions can fuel your success.
Image
Novata Solutions

Smart and effective
solutions for businesses.

Follow Us - Fb. / X. / Li. / yT.

© Novata Solutions

Head Office

Level 7, 12 St Georges Tce
Perth WA 6000

Contact Info

[email protected]
Ph 1300 NOVATA

Image

ISO 27001

Image

ISO 9001

Image

SMB 1001 Gold

Image

In the spirit of reconciliation Novata Solutions acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their Elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today. This land always was, and always will be Aboriginal Land.

Image

Novata Solutions is committed to embracing diversity and eliminating all forms of discrimination through education. We welcomes all people and is respectful of individual identities.