RE: SUS server

From: richard boswell (richardboswell@hotmail.com)
Date: 04/09/03

  • Next message: Lucas Zaichkowsky: "RE: VPN and ISA server"
    From: "richard boswell" <richardboswell@hotmail.com>
    To: focus-ms@securityfocus.com
    Date: Wed, 09 Apr 2003 18:26:09 +0000
    
    

    Since the topic of HIPAA and 21 CFR Part 11 has come up, does anyone know of
    a good reference with respect to security for both topics? I have looked in
    some places, maybe the incorrect ones, but I haven't discerned anything that
    seems applicable to my particular company (which is Healthcare, so you would
    think that I would have to find something somewhere). Any help is
    appreciated.

    Richard Boswell
    Corporare Network Manager
    Symbion Healthcare

    >From: "Brian W. Spolarich" <bspolarich@nephrostherapeutics.com>
    >To: "Evan Mann" <emann@pinnaclefinancial.com>,<focus-ms@securityfocus.com>
    >Subject: RE: SUS server
    >Date: Tue, 8 Apr 2003 11:14:12 -0400
    >
    >Evan Mann wrote:
    > > I've read the 21 CFR Part 11 spec and no where in the documents I've
    > > read does it make indications as to what controls you need on your
    > > systems in terms of updates to your OS and OS related files. 21CFR
    > > Part 11 is all about document control and/or electronic signatures on
    > > resources related to your medical business, not what can or cannot be
    > > done to the operating system itself.
    >
    > Typically the issue arises in controlled and regulated environment where
    >systems and applications that fall under regulatory scope (21 CFR Part 11
    >and GxP in particular) need to be validated for their intended use. This
    >typically requires a qualification process for the systems that the
    >applications are deployed on (Installation Qualification, Operational
    >Qualification, and Performance Qualification [IQ/OQ/PQ]), both server and
    >client depending on the architecture, and a detailed and documented
    >validation of the applications themselves.
    >
    > If you apply OS patches in an uncontrolled manner, you wind up with
    >validation exposures. e.g. "How do you KNOW the application continues to
    >behave as expected after you applied the patch? Did you test it?" So in
    >these environments patches tend to be applied less often an usually en
    >masse. I suspect many folks use the Service Pack releases as the
    >opportunity to do that, and only deploy critical interim patches when
    >absolutely necessary.
    >
    > In those environments, the very incremental approach that SUS takes is
    >probably not a Good Thing.
    >
    > -bws
    >
    >----------------------------------------------------------------------
    >Block Spam, Smut & Viruses
    >SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of
    >technology including filtering embedded and attached file content. Rid your
    >enterprise of unwanted content.
    >http://www.securityfocus.com/SurfControl-focus-ms2
    >Download your free fully functional trial, complete with 30-days of free
    >technical support.
    >----------------------------------------------------------------------
    >

    _________________________________________________________________
    The new MSN 8: smart spam protection and 2 months FREE*
    http://join.msn.com/?page=features/junkmail

    ----------------------------------------------------------------------
    Block Spam, Smut & Viruses
    SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of
    technology including filtering embedded and attached file content. Rid your
    enterprise of unwanted content.
    http://www.securityfocus.com/SurfControl-focus-ms2
    Download your free fully functional trial, complete with 30-days of free
    technical support.
    ----------------------------------------------------------------------


  • Next message: Lucas Zaichkowsky: "RE: VPN and ISA server"

    Relevant Pages

    • Re: Testing MS Security Patches?
      ... > be to test those applications on which your business depends. ... >>testing procedures before implementing MS security patches through out our ... Download the patch. ...
      (microsoft.public.security)
    • CFP: CLADE 2004-Challenges of Large Applications in Distributed Environments
      ... CLADE 2004-Challenges of Large Applications in Distributed ... Challenges of Large Applications in Distributed Environments ... variability in programming environments, heterogeneity of software and ... hardware platforms, dynamics, ad hoc behaviors and unreliability of ...
      (comp.lang.java)
    • Re: Anyone know why the Alpha market is so so quiet?
      ... they need to test their Apps before they release OS patches.] ... I think it would help if Ron pointed out exactly what testing he performs on ... each system and the hosted applications, after each one of these yum fests. ... Some VMS & Rdb patches, though, can't be *adequately* tested on the QA cluster because it's not as powerful as the main cluster and can't simulate the same load. ...
      (comp.os.vms)
    • Re: [PATCH 4/8][for -mm] mem_notify v6: memory_pressure_notify() caller
      ... reclaimation process rather than some other stage? ... If this feature is useful then I'd expect that some applications would want ... Some of the patches were wordwrapped. ...
      (Linux-Kernel)
    • Re: OS & Code Sharing
      ... a kernel, OS services available to all applications, and applications. ... programs are designed to cooperate with one another nicely and ... Design it that way. ... percentage of code sharing than other environments that I have used. ...
      (comp.lang.forth)