Nimstead Business guide

Patch coverage: unknown, stale and partial evidence.

Patch coverage describes the devices and applications your evidence actually covers. Unknown means there is no reliable assessment; stale means an observation may no longer represent the device; partial means some of the intended scope is missing. Keep those limits visible in every summary.

Unknown does not mean unaffected

An unknown assessment means the available information cannot support a reliable conclusion. Missing inventory, an unmatched application or an absent trusted vulnerability mapping should remain visible as uncertainty.

In the current Business development implementation, the real trusted vulnerability mapping catalogue is empty. Unmatched assessments remain unknown. The synthetic explorer demonstrates the workflow, not comprehensive live vulnerability detection.

Freshness matters

An observation describes a point in time. Stale evidence may no longer represent the device. Before deciding what to do, check the time of observation, the source and whether the collection was complete.

Partial is a result in its own right

A collection that covers some software or devices cannot establish the state of those it missed. Keep the missing part alongside the known part, especially when summarising for another person.

Example: eight observations do not cover ten devices

In an illustrative ten-device review, fresh inventory from eight devices leaves two devices unassessed. Even if all eight report the expected app version, the result only covers those eight observations. If one observation is old, record its freshness separately. Do not turn missing evidence into an “up to date” result for the whole group.

An exception is a management decision

Recording an exception explains why a finding is being handled differently. It does not remove the finding, install a patch or establish that a vulnerability is harmless. Keep the reason and scope with the evidence.

A report is a historical snapshot

Business has implemented historical JSON, CSV and HTML exports. They preserve recorded evidence for review; they are not a live assertion about an endpoint or a certification of compliance. A checksum can help identify a file, but it is not a digital signature.

Before sharing an export

Inspect its contents and choose an appropriate audience. Inventory and vulnerability information can reveal details about an organisation’s systems. The website uses only synthetic examples.

For the sequence of checks behind a conclusion, read patch assurance beyond installation success.

Read what exists today and what remains in development.