Our change management is driven by the business requirements and the risk associated with the particular vulnerability. We have a vulnerability classification scheme that drives the change management window based on the criticality of the patch. The change management windows are driven by business requirements, and the severity of the patches are based on a vulnerability’s severity, the company says. The company says the patch is designed to meet the business needs and the risks associated with a vulnerability. The patch is not only a patch, but a patch is required to be made to meet business requirements.”]
Source: https://www.csoonline.com/article/2117748/change-management-issues.html

