Re: Patch Management on Critical Servers (Healthcare)



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

beinm@xxxxxxxxx wrote:

I'm just curious to hear how people in the field have been handling patch management with critical servers. Have you setup maintenance windows? If, so how did you manage the down time? What have people been doing if the device or server has an approved FDA configuration? Are you using thing like WSUS?




Matthew,

I work for IBM's GSD and I support two hospitals in Manhattan and for
*nix servers patch management is handled at two levels. One: we have a
change management process where all changes have to be presented at a
meeting and approved, especially patching.

Patching is done through a series of automated scripts that pick from a
library of patches based on what is applicable to the environment and
the software installed on the system.

At another layer patching is first done on non-critical and development
systems prior to being applied to the production environment so any
issues with the patching can be caught and dealt with either by not
applying the patch at all in production (for instance bad patches from
Sun) or working with the applicable vendor to resolve the issues.

Once a battery of patching is slated for application to the production
environment the requisite change records are opened and presented at the
change meetings for the hospitals and dates set.

At both hospitals critical production systems have "mated pairs" of
servers. While these are not strictly speaking clusters or HA pairs for
logical purposes they can be considered so. Because we have this we can
schedule the patching so that only one half of a pair are affected at a
time. In other words we will patch one of the servers in a pair one day
wait a day or two and patch the other. This gives us additional
insurance from "bad patches" in that for a couple of historical cases we
have found issues with patches that didn't show up in our development
testing but did "under load."

As far as FDA affected systems go, we haven't had to deal with that
under the *nix environment yet but we'll cross that bridge if we ever
come to it.



- --
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Peter L. Berghold Peter@xxxxxxxxxxxx
"Those who fail to learn from history are condemned to repeat it."
AIM: redcowdawg Yahoo IM: blue_cowdawg ICQ: 11455958
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
Comment: Using GnuPG with Red Hat - http://enigmail.mozdev.org

iD8DBQFEX1oDUM9/01RIhaARAv5gAJ9uwsT8bgp3X56h80uzMNrxDqFNOwCglCZR
2a2A3orfSiuhu4KjGI8IY+g=
=/GtE
-----END PGP SIGNATURE-----

---------------------------------------------------------------------------
---------------------------------------------------------------------------

Relevant Pages

  • Re: Thank You - 12 Companies 1 Server
    ... Patches should only be necessary in EXTREEM cases - you make it sound ... and we didn't have good sources for patching information. ... For servers, I'm aware of the updates because of SUS, and I ... > Saturday - maybe an hour per month at most to patch the SBS and two other ...
    (microsoft.public.windows.server.sbs)
  • RE: patching servers...
    ... > Subject: patching servers... ... > and then let it run with the patch applied for a few days/week before ... I'm an advocate of standard configurations and fast patching. ... server hosed by Windows Updates once, but the way it had been set up ...
    (Focus-Microsoft)
  • Re: Enterprise Microsoft / application patching solutions?
    ... A place I used to work at had about 30k workstations and 2k servers used BigFix. ... there were different modules you could add into it to patch other applications as well. ... This solution would really be beneficial if it was able to do both Microsoft OS patching and application patching. ...
    (Security-Basics)
  • Re: Dedicated admin to handle patch management ?
    ... > servers they maintain. ... > Do you agree that a more effective approach is elect one sysadmin to ... The point would be to not only get the patching done as quickly as possible, ... As for workstation patch management - WSUS. ...
    (microsoft.public.security)
  • Re: problems with KB951746
    ... Do any of the four servers run *without* ISA? ... What I suspect is happening is that the patch is doing what it is supposed to do. ... If your firewall is not configured to allow DNS traffic from a random source port then your recursive DNS requests are being stopped at the firewall...and you'll get the symptoms you describe. ... It is also possible, but less likely, that your ISP's DNS servers are misconfigured and are unable to reply on odd source ports. ...
    (microsoft.public.windows.server.sbs)