Here’s a step-by-step recap of a very simple process to do security patching, in 3 simple steps!
This also assumes having first created a Deployment Template where no “Collection” was specified when created (I’m using “Lab SW Deployment” here; there is nothing fancy in it's configuration at all):
1. Select desired updates for deployment (this example uses a 3 month period of updates) in CfgMgr MMC Console using a SEARCH folder
a. SW Updates --> Update Repository --> Search Folders
b. R-click --> New Search Folder
c. In the wizard, select “Date Released” --> Date Released=Last 3 months; Vendor= Microsoft; and Search All Folders Under This Feature (and give the folder a name)

d. Sort the resulting list created by “Required” column (descending so all needed updates are at the top of the list)
e. Select all “Required” updates; r-click and select “Update List” to create a new Update List (“Lab SW Update List” in my example)
f. Launch the Update List Wizard to “Create a new update list”

g. Next, next, next, Finish – very simple and straightforward
2. Navigatein the Consle to the Update List --> Lab SW Update List and select your new Update List
a. Don’t forget to refresh console to display the new list!
3. Now simply DRAG-n-DROP the “Lab SW Update List” onto the desired Deployment Template (“Lab SW Deployment” in my example)
a. This “Drop” launches the “Deploy Software Updates Wizard” and deploy as usual/desired.
b. Done!
So this becomes nearly as simple as 1/2/3 (create a desired Deployment template first):
1. Create a Search Folder and select desired timeframe for Updates required;
2. Create an Update list of all “Required” updates
3. Drag the new Update List onto the desired Deployment template to launch the DSUW, and DONE