Patch management factors

From: mrmagic (tomgerace_at_gmail.com)
Date: 01/30/05

  • Next message: choowie: "Compiling Nessus on Mandrake 10.1"
    Date: 29 Jan 2005 19:22:45 -0800
    
    

    In our organization, enterprise operating system patch management is
    considered to be a process, not a product. This process consists of
    many factors, determined by policy, software behavior, and enterprise
    needs, that all contribute to the success of the implementation.

    >>From the start we determined a set of requirements, or factors, that
    were essential to the successful implementation of an enterprise patch
    management process within the Freeman School. Our requirements
    included the following mix of administrative and software factors:
    · Administrative support for the school-wide process from the highest
    level down
    · User notification about process well before the actual start of the
    process
    · Retraining the user community to keep their computers on all the
    time and restart daily
    · Central control of "pushing" updates and patches to computers
    · Testing patches before general distribution
    · Segregation or grouping of computers (lab, classroom, faculty,
    staff, researcher)
    · Define different update behavior (patches, time of day, restart)
    for defined groups
    · The ability to control post-update restarts (specifically to
    prevent restart after update for faculty and researcher computers)
    · Include Microsoft Office and key back-end products in the process
    · Good pre- and post-update reporting

    While we determined that these factors were essential to our specific
    patch management implementation, we believe that a set of factors
    exists that is essential to the successful implementation of any patch
    management implementation in any organization.

    If you have implemented enterprise patch management, what factors or
    requirements do you believe were most important in the successful
    implementation of your patch management process?

    If you are considering implementing enterprise patch management, what
    factors or requirements do you believe will be most important to a
    successful implementation in your specific environment?
    Thanks in advance.

    Tom


  • Next message: choowie: "Compiling Nessus on Mandrake 10.1"

    Relevant Pages

    • RE: Windows Update Services
      ... Reporting is not where it should be for an enterprise patch management ... a grilled cheese - not an SMS "lobster thermador". ... Subject: Windows Update Services ...
      (Focus-Microsoft)
    • Re: Sun support (well, SUC anyway) stinks ... P U
      ... omitted to integrate it with patch management. ... with SMF everything seams to be at hand... ... under SMF are implemented to allow a restart, a lot of reboots would be ... Patches for kernel modules and .so's which are not loaded/used ...
      (comp.unix.solaris)