Michael Cooney
Senior Editor

The dog days of patch management

Opinion
Jul 30, 20032 mins

* How users are dealing with the problem of patch mangement

Without much doubt, patching software is a disruptive, time- and resource-consuming process –  requiring IT departments to test any new software patch before applying it, scheduling downtime for machines to apply the patch and ensuring it doesn’t “break” applications.

Our Special Focus author this week, Ellen Messmer (emessmeer@nww.com), writes that patching for security purposes also means managers have to be on constant alert for news of any new holes found in vendor products. This thankless task monopolizes large chunks of IT staff time, in spite of a growing array of products and services that can track machines that need patches and automate patch downloads from vendor sites.

Commercial patch-management products can be stand-alone patch products like those from BigFix, PatchLink, St. Bernard Software and Shavlik Technologies, or the patch component of systems management products from ConfigureSoft, Ecora, IBM Tivoli and LANDesk Software.

And the number of vendor patch releases is skyrocketing as the number of newly discovered vulnerabilities increases dramatically. “The number of software vulnerabilities has doubled every year since 1999,” says Casey Dunlevy, manager of the CERT Analysis Center at Carnegie-Mellon University, which tracks this data as part of its ongoing effort in issuing the closely watched CERT security alerts. “Last year it was 4,200 different vulnerabilities in software products, the year before it was 2,100,” Dunlevy says. “And it looks like we’ll double it again this year.”

That’s a scary and tedious proposition. Find out how users are dealing with this problem: https://www.nwfusion.com/news/2003/0728specialfocus.html