Quantcast
0
0

Guide to Patch and Vulnerability Management

NetworkWorld

Wednesday, May 14, 2008 12:00 PM PDT

Patch management best practices

A systemized approach eases the work of managing patches

by Network World Staff
  • Create an enterprise group responsible for identifying, testing and executing patches. Members should include people from the security team and daily operations. The team should include patches in an overall change-management workflow so that less critical patches will not wait long to be tested and deployed. Such patches will instead be rolled out on a similar schedule as other upgrades, feature changes and the like.
  • Use a phased approach to applying live patches. First apply them to a small test group of users before a universal patch. When working with the small test group, reboot after each patch, rather than after the entire set of patches, to help identify which patch may be troublesome.
  • Standardize IT configurations wherever possible. Obviously, though, no one has a completely standardized IT infrastructure. So in your test group for live patches be sure to include a sample for each typical configuration that you will routinely ask the patch management product to update.
  • Include a measurement phase after each patch is implemented. This should measure current levels of susceptibility to attack, but should also document the time needed for patching and the cost for patching. This will help you make informed future business decisions on the patching process.
  • Automate the patch management process as much as possible.
Community Comments

PC World's Marketplace

PC World's Free Whitepapers

Security News
More

Latest Expert Blogs

All Blogs
Featured Resources

Premier Content From Our Sponsors

Featured Whitepapers

White papers, case studies and product info from top brands

  • The 5 Reasons to Worry about Your DNS DNS servers are one of the most critical, yet vulnerable, network infrastructure applications. Because of their exposure to the Internet, they are among the most vulnerable computers that an organization deploys. This whitepaper explains the top fi...
Featured Webcasts

Watch webcast presentations and videos from industry thought leaders on today's most important business and technology topics. For free.