What are the order of events for identifying, applying and seeing those updates w/in DC patch mgmt?

What are the order of events for identifying, applying and seeing those updates w/in DC patch mgmt?

This is the order we've done:
      Update Vulnerability DB
      Scan Systems
      Create Config of Highly Vulnerable Systems and Deploy
      After Config completes, Re-Scan
      Several of same systems still show with same Vulnerabilities
      Re-create Config of those systems
      Almost all systems show "Patch is not applicable"...
 
Are we doing something wrong or is there a different cycle in which a system that was targeted as needing a patch has been identified as resolving that patch from the manual Scan Systems under Patch Magmt tab?
 
Also, how often does the CD server Scan for Vulnerabilities on the Clients?  I do not see a schedule for that anywhere?  If it doesn't is there a way to schedule the scan?

                  New to ADSelfService Plus?