Need patch policy help

view story

http://www.unix.com – I'm working on developing a patch policy for a mid-size and quickly growing company. Patches have been at the bottom of the totem pole for years. I possess the ability and care enough to straighten it out. However I'd like some others input on the best way to handle the patch policy. From when a patch is released how is communicated? How long to deployment? etc.. What are your trusted sources for patch alerts? (HowTos)