Home > Security All-in-One Guides > Compliance > Technology > Vulnerability management > Products of the Year: Patch management
All-in-One Guides: Compliance:
EMAIL THIS
 START   SOX SCHOOL   INFOSEC-RELATED REGS   STANDARDS   PROCESS IMPROVEMENT   PEOPLE & POLICY   TECHNOLOGY   AUDITS   
Technology


Vulnerability management
<< PREVIOUS | NEXT >>: 2006 Products of the Year: Vulnerability...
 TIPS & NEWSLETTERS TOPICS 

SECURITY BUYER'S GUIDE

Products of the Year: Patch management


Information Security magazine
01.04.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


GOLD MEDAL: BigFix Patch Manager
BigFix, www.bigfix.com
Rating: 86

BigFix Patch Manager and its underlying "fixlet" technology continue to wow the security market. Its ease of use, customization and platform independence make it a top choice among enterprises and Information Security's gold award winner for patch management.

"BigFix is simply comprehensive," says a CISO of a large financial service company.

Automated patching has been around for a few years, but the reach and reliability has hampered many deployments. Most service Windows environments well, but have a harder time reaching across to other platforms and applications. Capabilities have proven problematic, since not all tools can discover, push and verify patch installations with a high degree of accuracy. Enterprises have been forced to use either homegrown or multiple COTS tools to fill their needs.

What enterprises like about BigFix is that it's fully automated and customizable, can push patches to specific machines automatically or on demand, and can analyze and generate reports for measuring patching successes. Even better, it can change configuration settings, making it a good instrument for hardening boxes and employing workarounds if a patch isn't available.

Fixlets are the things that make BigFix work so well. They monitor a machine for vulnerabilities and configuration settings. They communicate with the server, which will push appropriate fixes to either patch the system or bring its configuration into compliance with defined security policies.

This is more than just some client-server architecture. Fixlets are more like applets, and that small footprint makes them easy to deploy, update and manage. Each fixlet can carry a broad range of instructions, making them extremely flexible in implementing changes. Enterprises praise BigFix because it gives them the ability to use either fixlets provided by BigFix or, using an editor, create their own.

Security managers appreciate the tremendous degree of control and information they get from fixlets, providing a wealth of intelligence about the enterprise's or a particular machine's security posture.

With this kind of flexibility and reach, it's easy to see why BigFix Patch Manager has become one of the most popular security tools on the market.

SILVER MEDAL: PatchLink Update
PatchLink, www.patchlink.com
Rating: 84

USER COMMENT: "PatchLink Update is easy to use. PatchLink (the company) is responsive to customers' needs and has a commitment to excellence."

BRONZE MEDAL: Windows Update Service
Microsoft, www.microsoft.com/security
Rating: 71

USER COMMENT: "Microsoft's patch management might lack a couple of features, but it's good enough overall, and it's free."

MORE 2004 PRODUCTS OF THE YEAR


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Technology,   Vulnerability management,   Compliance,   Security Buyer's Guide,   Application and Platform Security,   Enterprise Vulnerability Management,   Security Patch Management,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>: 2006 Products of the Year: Vulnerability...
VIEW ALL IN THIS CATEGORY

RELATED CONTENT
Vulnerability management
NetChk Protect 5.5
2006 Products of the Year: Vulnerability management
Review: New Hailstorm a viable in-house pen test option
Configuresoft's Enterprise Configuration Manager v4.7
Hercules 4.0 Enterprise Vulnerability Management Suite
REVIEW: nCircle's IP360 especially helpful for Cisco shops
Pitching patch: RFP bakeoff

Security Buyer's Guide
Keystroke dynamics makes BioPassword Internet Edition a viable authentication option
Access security with KoolSpan's SecurEdge
NetChk Protect 5.5
Biometrics: Best practices, future trends
2006 Products of the Year: Emerging Technologies
Secure Sphere 2.0
Scan & Deliver: SLAs force service providers and outsources to hit the mark ... or hit the road
Secure remote access: SSH Tectia Manager
Spycatcher Enterprise 3.2
Configuresoft's Enterprise Configuration Manager v4.7

Security Patch Management
Squad: Tokenization, Phishing and the Feds
Should management processes change based on a patch release schedule?
Should Windows Mobile updates come from Microsoft?
Adobe updates ColdFusion, JRun, Flex
Trusteer CEO criticizes Adobe, touts better patch deployments
Patch management study shows IT taking significant risks
Vulnerability mitigation study shows need for faster patching
Microsoft to issue security report card, new tool at Black Hat
How to manage patches for Adobe
When is it suitable to remove Java updates?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
attack vector  (SearchSecurity.com)
back door  (SearchSecurity.com)
ethical worm  (SearchSecurity.com)
Patch Tuesday  (SearchSecurity.com)
zero-day exploit  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts