This paper provides a guide to Critical National Infrastructure organisations on Patch Management. It describes a four-stage process for ensuring that all systems are appropriately patched to minimise security vulnerabilities, and describes a system of metrics that organisations may use for measuring the effectiveness of their patching strategy.