Patch Management
Home > Ask the Security Experts > Platform Security Questions & Answers > What is an ideal patch management process for small businesses?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What is an ideal patch management process for small businesses?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 22 August 2007
Should patch testing be a priority for both small and large organizations? For smaller groups that just don't have the resources, are there testing steps that can be skipped or shortened?

>
EXPERT RESPONSE
I sympathize with organizations -- large and small -- when it comes to patch management. It can be a time-consuming and resource-hungry task. The sheer number of Microsoft patches alone makes it cost-prohibitive to test all of them prior to implementation. Let's look at how a smaller organization can streamline the process.

Firstly, consider the patch management process. It starts with scanning systems for missing security patches. Thankfully, the task is now mainly an automated one. Next comes assessing whether the issue that a particular patch addresses is actually a threat to your current environment. Making that kind of decision is a lot easier if you have a system inventory that prioritizes all of your machines. Developing a business profile for each application will help enormously in assessing system importance, allowable downtime periods and vulnerability risk levels. Profiles should list expectations from the IT infrastructure, as well as end users. Such requirements can help to prioritize your efforts. Vendor-reported criticism is another key input for calculating a patch's significance. It's important to be aware of known exploits that use a given vulnerability as an attack vector.

But do remember that patches are not mandatory. The threat posed by a particular flaw may be within your risk tolerance, while some patches won't be relevant to your system and won't need to be tested or installed.

Once you have decided that a patch needs to be deployed, it should be prioritized as either a normal or emergency change. Emergency patches should be implemented immediately, while less urgent patches can be tested and deployed when time is available. Unfortunately, when it comes to the actual testing process, there aren't really any shortcuts. Testing is required because patches can overwrite working drivers, disrupt existing software and change services or functions on which your system relies.

Larger organizations can use a virtualized IT infrastructure to provide test environments, cutting ownership costs and implementation time. Test computers are another luxury, but they may be unavailable to administrators of smaller networks. If you don't have that privilege, you should at least test each patch on your own PC. Every problem you see on your own system is one less problem that you will hear about from each of your users. Be sure to have a rollback and restore plan in place though! It is also important to frequent the relevant Internet discussion news groups to find out others' experiences with a particular patch.

By completing a patch test, you can ensure a predictable rollout when it is deployed. Unfortunately, you cannot batch-test patches; if testing produces an unsatisfactory result, you must identify the exact cause of the problem before going any further. If you have installed several patches at once, finding the root of the issue will be tricky. Production rollouts can be used as an additional part of the testing process, though, if they are done in stages. The initial rollout should be to less critical systems, and if the patches perform as expected, continue with the rollout until all systems are updated.

Finally, document your decisions to install or reject specific patches so that you can provide assurance that vulnerabilities have been identified and appropriate patches have been installed. Your security policy should define your organization's stance on patch prioritization, testing and deployment.

More information:

  • Michael Cobb explains how to install the most current Microsoft patches and critical updates in one go.
  • So you push critical Windows patches once a month. But what about Acrobat Reader, QuickTime and your other third-party applications?


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Platform Security
    Is attack code valuable for vulnerabilities or just a publicity stunt?
    Will the features of Windows Vista SP1 encourage wider adoption of the OS?
    Is a Master Boot Record (MBR) rootkit completely invisible to the OS?
    Are open recursive DNS servers inherently insecure?
    Should whole disk encryption products be used with data backup software?
    Which operating system can best secure an FTP site?
    Is desktop virtualization a realistic enterprise option?
    Does FTPS encrypt data packets at the hardware or software level?
    Should disks be encrypted at the hardware level?
    Is Triple DES a more secure encryption scheme than DUKPT?

    Patch Management
    Database patch denial: How 'critical' are Oracle's CPUs?
    Researchers defend study on patch distribution insecurities
    Microsoft patches Bluetooth, Internet Explorer flaws
    Is attack code valuable for vulnerabilities or just a publicity stunt?
    Information security book excerpts and reviews
    Microsoft Jet Database Engine update could be issue for admins
    Inside MSRC: Microsoft explains Word, Publisher flaws
    Oracle fixes 41 flaws in April CPU
    Researchers warily watch for Microsoft GDI exploits
    Oracle preps CPU for 41 flaws

    Creating and Managing Information Security Policies
    Security Awareness Training Essential Part of Infosec Program
    How to lock down instant messaging in the enterprise
    Worst practices: Bad security incidents to avoid
    Thompson calls for marriage of data and security management
    Companies Collecting Too Much Customer Data Increase Exposure
    Interview: Arizona CISO David VanderNaalt
    Incident response success in five quick steps
    Social networking Web site threats manageable with good enterprise policy
    IT GRC: Combining disciplines for better enterprise security
    Security management in 2008: What's in store
    Creating and Managing Information Security Policies Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    attack vector  (SearchSecurity.com)
    back door  (SearchSecurity.com)
    ethical worm  (SearchSecurity.com)
    Patch Tuesday  (SearchSecurity.com)
    zero-day exploit  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts