Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS


Security /
Andress on Security /

Patch Management Policy

I hear a lot of debate these days on patch management – it’s a losing battle, patches break my machines, developers should write better code, etc. While I agree that all these statements are true at some level, patch management is still not an area administrators can ignore.

When I refer to patch management, I am not strictly referring to Windows systems. Organizations need to have formal patch management policies and procedures for all operating systems they use. Patch management policies must be designed to work within your organization’s existing maintenance program, but here is a standard policy that I always start with:

1. A designated group or individual is responsible for monitoring security mailing lists, vendor mailing lists, and specific web sites for the release of new patches.

2. New patches are reviewed and evaluated for relevance and criticality to the organization’s infrastructure. This step should occur within 24 hours of release of the patch.

3. If the patch is considered critical and active exploits exist, the patch should be installed as soon as possible. If the patch is critical and active exploits are not yet in the wild, patch installation can wait until the next scheduled maintenance window or until active exploits are released, whichever comes first.

4. For non-critical patches, installation can occur during regularly scheduled maintenance windows.

Don’t forget that all patches should be thoroughly tested before deployment.

A number of patch management products are on the market to help with this process, and I reviewed several of them in the past. (http://www.nwfusion.com/reviews/2002/0204bgrev.html) A new site is also online, www.patchmanagement.org, to discuss these very issues. I encourage you to subscribe to the mailing list and keep an eye on the site as they continue to expand its content.


Back to the Andress on Security


Comments

Post a comment

Name:


Email Address:


URL:


Comments:


Remember info?



« Introduction | Comdex 2002 Report home

RSS feed
Put Network World Comdex 2002 headlines on your site.

Apply for your free subscription to Network World. Click here. Or get Network World delivered in PDF each week.

Get Copyright Clearance
Request a reprint or permission to use this article.

To top

NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.

Send this article to a colleague

Please select a type of format for the e-mail you want to send:
Text
HTML
Recipient's name:

Recipient's e-mail:
Your name:

Your e-mail:
Comments:

Feedback

Tell us your thoughts on this page or the issues raised in it. We'll cc: the author and editors on all comments.

Comments:

Name:
E-mail address:

Can we post your comments in an online forum on the topic?
Yes No

What did you think of this article?
Very useful Somewhat useful Not at all useful

Would you want to see:
More articles on this topic
Fewer articles on this topic

Thank you! When you click Submit, you'll be taken back to this page.

* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.