Installing patches without testing them

Installing patches without testing them

Do you recommend installing patches without testing them first? I installed a patch for Windows NT 4.0 SP6 that resulted in disabling the session manager. There was no alternative but to return to the last backup image copy. Unfortunately, this was several patches back.


    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

I would never recommend installing a patch without testing its effect on the environment in place. Having a QA environment that mirrors your live environment will always help ensure patches work correctly. I suggest convincing your management team to approve QA equipment to mirror your live equipment in order to properly test your patches and updates. If the uptime of your live equipment is important to company revenue this should be a worthwhile investment. Of course, nothing is 100% accurate so always make sure the patch is needed before installing.


For more information on this topic, visit these other SearchSecurity.com resources:
  • Featured Topic: Patchwork overload
  • Ask the Expert: Testing security patches
  • Best Web Links: Patches/patch management


    This was first published in October 2002