PLA report

The Protection Level Agreement (PLA) report measures how long endpoints remain exposed to known security issues after a patch becomes applicable to them, and compares that exposure against the remediation time frames agreed for your BigFix environment.

This analysis shows the current state of your environment against several sample Protection Level Agreements (PLA).

Each PLA definition contains following elements:
  • Content (i.e. the set of in-scope Patches for the given PLA)
  • Endpoints (i.e. the set of in-scope endpoints against which to measure the PLA)
  • Time (i.e. the target time frame within which the content should be addressed for the given Endpoints)

How PLA compliance is calculated

For each computer and Fixlet in a designated patch group, the exposure duration is the time between when the patch became applicable to your environment and when it was fully remediated — or the current date, if it is still applicable.

The calculation uses three timestamps that BigFix tracks for every Fixlet result:

  • Last Became Relevant — when the Fixlet most recently became applicable to the device.
  • Last Became Nonrelevant — when the patch was successfully applied and the vulnerability was remediated.
  • Relevant flag — the current status indicating whether the Fixlet is still applicable.

Exposure duration = time from Last Became Relevant to Last Became Nonrelevant — or to the current date, if the Fixlet is still relevant.

Note:
The calculation is anchored to relevance dates, not the vendor release date. The release date that you specify when creating a patch group only filters which Fixlets are in scope for the PLA; it does not start the exposure measurement. The exposure clock for each device starts when the patch becomes applicable to that device and stops at remediation.

Why the last became-relevant time is used.BigFix uses the last time a Fixlet became relevant (not the first) so that real-world patching scenarios are measured correctly. For example: a patch is applied on Monday (the Fixlet becomes nonrelevant); a user reverts the patch or restores a previous snapshot on Wednesday (the Fixlet becomes relevant again). The true exposure window is from Wednesday onward. Using the last became-relevant time captures the full exposure time even if a patch was previously applied and then removed.

Example calculations

  • Example 1 — Successfully patched Fixlet. Fixlet A became relevant on Aug 1, 2026 and became nonrelevant (patched) on Aug 5, 2026. Exposure duration: 4 days.
  • Example 2 — Unpatched Fixlet (still relevant). Fixlet B became relevant on Aug 10, 2026 and is still relevant (not yet patched) on the current date, Aug 28, 2026. Exposure duration: 18 days, and continuing.
  • Example 3 — Patched after an extended period. Fixlet C became relevant on Aug 4, 2026 and became nonrelevant (patched) on Aug 14, 2026. Exposure duration: 10 days.

Calculating average exposure

When a patch group contains multiple Fixlets, BigFix averages the exposure durations: Average = sum of all durations ÷ number of Fixlets. Both patched and still-relevant Fixlets contribute — unpatched systems add their current, still-growing exposure time to the average. For the three example Fixlets above: (4 + 18 + 10) ÷ 3 = 10.67 days.

Table 1. Average exposure example
Fixlet Duration Status
Fixlet A 4 days Patched
Fixlet B 18 days Still relevant
Fixlet C 10 days Patched
Average (4 + 18 + 10) ÷ 3 = 10.67 days —

Compliance status

A patch group is compliant when its average exposure duration is within the agreed PLA target, measured from when each patch became applicable. The default PLA target is 30 days. In the example above, 10.67 days is within a 30-day target.

A patch group is noncompliant when the average exposure duration exceeds the PLA target, or when at least one required patch remains unpatched beyond the target time frame measured from when it became applicable. In the example above, if Fixlet B continues unpatched past day 30, the patch group becomes noncompliant even if the other Fixlets are remediated.

Note:
On newly onboarded endpoints, exposure clocks start when Fixlets first become relevant on the enrolled device. A recently deployed environment can therefore report short exposure durations — and a compliant status — even for patches whose vendor release dates are months old.

PLA chart

A typical PLA chart shows the timeline taken to patch the vulnerability in an environment.

The color on the bar represents the following:

  • Agreed PLA: The timeline defined to patch the vulnerabilities.

  • Within PLA: The grey portion of the bar represents the number of vulnerabilities that are patched within the agreed PLA timeline.

  • Beyond PLA: The purple portion of the bar represents the number of vulnerabilities that are yet to be patched. These vulnerabilities are way past the agreed PLA timeline and possess a greater risk to the devices.

Mouse over on the bar to see the patched vulnerabilities.

Select PLAs

Users have the ability to establish their own designated Protection Level Agreement (PLA) periods to effectively manage ongoing mitigation efforts tailored to their specific business requirements. By specifying an agreed time, users can easily monitor their progress towards achieving the pre-determined targets. The designated time frames can be modified by adjusting the provided sliders, with the minimum PLA target set at 1 day and the maximum at 180 days.

Filter Devices

To define the group of computers for PLA calculation, navigate to Select PLAs and click Filter Devices.

Add Patch Group

To create a custom Patch Group, navigate to Select PLAs and click on Add Patch Group. Provide a Patch Group Name, specify severity, category, release date and source of the patch. Save your changes.

Note:
Administrator privileges in Web Reports are required to create custom PLAs.
Note:
The release date acts only as a content filter — it selects which Fixlets belong to the patch group. It does not set the starting point of the exposure measurement. For how compliance is measured, see How PLA compliance is calculated.

Only Fixlets that carry a source release date, a source severity, a category, and at least one CVE ID are evaluated for a patch group. Patches whose Fixlets lack any of these fields do not appear in the PLA calculation.

CyberFOCUS Category

The following table shows the mapping between the CyberFOCUS external content categories and Fixlet categories:

CyberFOCUS category Fixlet category
BUG FIX

Bug Fix

Bug Fix Advisory

Bug

ENHANCEMENT

Definition Update

Definition Updates

Feature Pack

Hotfix

Update

Updates

Product Enhancement Advisory

ENHANCEMENT

Recommended

Optional

Upgrade

SERVICE PACK

Rollup

Service Pack

Update Rollup

SECURITY

Critical Update

Critical Updates

Security

Security Advisory

Security Hotfix

Security Setting

Security Update

Security Updates

SECURITY

Mandatory

Severity Mapping

The following table shows the mapping between the CyberFOCUS Severity categories and Fixlet Severity Field categories:

Table 2.
CyberFOCUS Severity Fixlet Severity Field
CRITICAL Critical, Mandatory, High
IMPORTANT Important, Recommended
MODERATE Moderate, Medium
LOW Low, Optional, Negligible
UNSPECIFIED Unspecified, NA, and empty values

Export data

To export PLA data click Export and select Export PLA (.pdf).

Patch Details Pane



The Patch details pane provides additional information about the patch. For example, Java patches, critical server patches. This pane is dynamically updated based on the where you mouse over the PLA chart.

This pane shows if the PLA objective of a patch is met or not and overall information of the patch such as PLA definition, content scope, time scope and machine scope.

PLA Table

The PLA chart is represented in a tabular format and contains the following columns:

Category: Device category.

PLA-Title: Name of the patch.

Target: Number of days provided to address the vulnerability.

Actual: The measured average patch exposure duration, in days, for the patch group.

Variance: The difference between target and actual.

Content items: Number of Fixlets available in the patch, click on the number to see the list of Fixlets.

Machine scope: Number of devices applicable to patch type.

See also