"So, do you think Automatic windows patch management and manual tomcat patch management would ideal as patch releases from Tomcat is very rare?"
Yes, that's the way we do it. We use WSUS for Windows patch management, and manually upgrade Tomcat as needed. This has not been an issue for us, as Tomcat is only updated a few times per year, not once per month like Windows is. If your environment is standardized enough, you could probably build your own MSI installer for Tomcat to make the upgrade process even easier. I've not done this, but there are inexpensive tools that you can get to help you do it. Brian