Home > Security Tips > Tech Tips > Managing the patchwork mess
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

TECH TIPS

Managing the patchwork mess


Mandy Andress
10.09.2002
Rating: -4.33- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


No system is immune to viruses. Unfortunately, discovering these security weaknesses is usually left up to virus and worm writers and hackers. If you aren't the first one attacked, there are usually patches available to inoculate your system. Writer Mandy Andress discusses a procedure for keeping your patches installed and up-to-date on InformIT. Here is a bit about that procedure and a list of sites you can visit to find out about new patches.

Identifying vulnerabilities, finding the correct software patches, downloading the code, installing the security update in the right sequence (assuming that you've selected the correct fix for your application version) and validating effective installation is quite a process. Plus, keep in mind that all of this needs to be done before hackers send notice to your firm in their own special ways.

You need to create a system to manage security updates and patches for your software, including operating systems, business applications, Internet access and even security applications. Although creating a security update system is daunting, after you've got one, your company should be able to keep on top of the security maintenance challenge.

Surprisingly, just a few steps can help you update and protect your systems against common exploits. Because small businesses don't have the myriad software and network configurations that large corporations do, you should be able to keep track of security updates easily if yo



u're systematic and take these precautions:

Don't delude yourself. Even if you have no resources for a dedicated security staff person, a security updating and patch documentation system is mandatory. If you outsource security or software updates, you should expect the vendor to send you its patch logs at your request. If the firm resists your request or you experience slow or no delivery, you might want to reconsider your choice of outsourcing companies.


Mandy also provides a nice list of sites to visit to find out about security patches.

The SANS Institute proposes the 10 most critical Internet security threats at http://www.sans.org/topten.htm. CERT also supplies a host of information to improve your security, as does ZDNet's Security IT Resource Center.

Here are some other helpful sites listed by system:

Microsoft: http://www.microsoft.com/technet/security/current.asp

Sun: http://sunsolve.sun.com/pub-cgi/secBulletin.pl

Linux: Red Hat: http://www.redhat.com/apps/support/updates.html Caldera: http://support.calderasystems.com/caldera?faq&15-10 Linux-Mandrake: http://www.linux-mandrake.com/en/security/ SuSE Linux: http://www.suse.com/us/support/security/index.html Debian: http://www.debian.org/security/

Cisco: http://www.cisco.com/warp/public/770/


Read about Mandy's advice on signing up for mailing lists over at InformIT. Registration is required, but it's free.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Common Vulnerabilities and Prevention Tips,   Tech Tips,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Common Vulnerabilities and Prevention Tips
What's your infosec IQ?
IE update clears up spoofing issue
Countdown begins for Mydoom DDoS attacks
Microsoft to disable spoofing syntax in IE
IE flaw could fool users in illicit downloads
Mydoom variant targets security features, Microsoft
Hackers scanning for ports opened by Mydoom
Dangerous, familiar application vulnerabilities top list
Potent Mydoom worm flooding inboxes
Worm opens two backdoors, logs keystrokes

Tech Tips
Video: The foundation of an email security strategy
Biometric authentication know-how: Devices, systems and implementation
The 5 A's of functional SAN security
Effective storage security policies
Smart options for safeguarding stored data
Outfox SOX: How to make regulations work for you
Roberta Bragg's 10 Windows hardening tips in 10 minutes
Using free network intrusion detection and prevention tools to stop hacks
Hacker techniques and exploits: Prevent system fingerprinting, probing
How to stop hacker theft: Employee awareness, risk assessment policies

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts