Deploy patches to your software and firmware as quickly as possible. Enable automatic updates whenever possible.

SLA for Patching According to CVE

What is SLA?

A service-level agreement (SLA) is a contract between a service provider and its customers that documents what services the provider will furnish and defines the service standards the provider is obligated to meet.

source: techtarget.com

Have you set up a maximum update time for your workstations/servers/softwares? If yes, do you take into account criteria such as the CVSS (Common Vulnerability Scoring System) score, the fact that the server to be patched is on the Internet-facing or not, that the flaw is known to be exploited (0-day)?