Remediation & Patching
Once something risky is in your inventory, decide what to fix first, test the fix safely, and ship a hardened configuration.
Policy keeps new risk off the install path; remediation deals with what is already in your inventory. This section ranks what to patch first by real-world exploit signal, lets you rehearse a patch before rolling it, packages a hardened configuration, and answers the “are we affected by CVE-X?” question every team eventually gets asked. Chainsaw ranks and rehearses; it does not open the upgrade PR — that stays with your existing patch tooling.
Where to next
The inventory and SBOMs these guides query come from Provenance & SBOM; roll a hardened config out org-wide from Monitoring & Compliance.