Home > Enterprise Desktop News > What is patch management?
Enterprise Desktop News:
EMAIL THIS

What is patch management?

By Anne Stanton and Susan Bradley
22 Dec 2004 | Ecora

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

The complete patch management book Get a glimpse inside the e-book "The complete patch management book" by Anne Stanton, president of Norwich Group, and Susan Bradley, Microsoft Small Business Server MVP. This series of book excerpts will help you navigate Chapter 1, "What is patch management?," courtesy of Ecora. Click for the complete book excerpt series.


What is patch management?

We define patch management as "the act, manner or practice of managing, handling, supervising and controlling the application of code to software in order to fix a bug, especially as a temporary correction between two releases."

Many in our industry consider that patch management means applying security fixes that are typically not temporary corrections. In fact, patch management and its processes include the entire area of introducing "new code" into an existing environment.

While this document focuses primarily on tools used for testing, supporting and evaluating Microsoft security patches, the basic concepts are the same for all software systems. IT managers and admins must logically control the introduction of new code into a network.

Computers drive world business. No longer can a financially healthy firm exist without technology. Further, maintaining, protecting and securing computer systems is, as recent legislative initiatives make clear, simply good business. A computer, like any mechanical device, requires regular maintenance. Applying patches to systems that connect to the Internet is simply and fundamentally mandatory. Period.

This document focuses only on the processes and procedures for patch management. We assume that you have taken steps to harden systems, apply firewalls and install antivirus protection. Patch management is only one of the steps needed to protect an environment, but it is an essential element nonetheless. We also assume that you understand the "business" reason for patching and that you have the proper buy in from management to add patch management to your security processes.

Some security vendors recommend installing the bare minimum of patches; however, that still means that you must rely upon consistent and appropriate processes and procedures.

History of patching

The CERT Guide to system and network security practices has small sections on software patches. The author, Julia Allen recommends applying patches on redundant or duplicate systems before applying them to main production machines. Any vendor service level agreement (SLA) should clearly state that firewalls should remain in place during installation of operating system patches. Allen further argues that those in charge of firewall operating systems and software need to review those devices as well for updates. Not too long ago, "best practices" meant not applying software patches in a piecemeal manner, but waiting for the cumulative security patch that, presumably, was more tested. Now, delay and deferral invite crisis.

Footnotes: "Threats and countermeasures: Security settings in Windows Server 2003 and Windows XP," (Redmond, WA: Microsoft, Inc., 2004); Allen, Julia H. The CERT "Guide to system and network security practices," New York: Pearson Education, 2001.

Click for the next excerpt in this series: Definition of Microsoft patches


Click for book details or get more information from Ecora.


Tags: Patches, alerts and critical updatesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Patches, alerts and critical updates
Microsoft releases six patches for November
Structuring patch management in seven steps
Underlying causes of inconsistent patch management
Microsoft's Online Desktop Manager caters to small IT shops
Microsoft's Patch Tuesday brings a bumper crop of security fixes
Act fast with five critical September patches
Microsoft's August patches run the gamut
Patching third-party browsers adds more work in Windows shops
Troubleshooting Microsoft WSUS connectivity issues
Windows security tools for the busy desktop administrator

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
drive-by download  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Windows Desktop Technology - Virtualization, Virtual Infrastructure, Virtual Desktop
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts