This document provides guidance on developing a patch management program for industrial control systems. It recommends including the following elements: a configuration management program, patch management plan, backup/archive plan, patch testing, incident response plan, and disaster recovery plan. These elements work together to help assess vulnerabilities, test patches, and recover systems if issues arise. The document also discusses specific issues to consider for patching control systems, such as operational impacts, and provides recommendations for evaluating vulnerabilities and deploying patches.