Home > Enterprise Desktop News > Why do we patch?
Enterprise Desktop News:
EMAIL THIS

Why do we patch?

By Anne Stanton and Susan Bradley
22 Dec 2004 | Ecora

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

The complete patch management book Get a glimpse inside the e-book "The complete patch management book" by Anne Stanton, president of Norwich Group, and Susan Bradley, Microsoft Small Business Server MVP. This series of book excerpts will help you navigate Chapter 1, "What is patch management?," courtesy of Ecora. Click for the complete book excerpt series.


Why do we patch?

It is obvious that we patch because software is not processing commands correctly. This mis-processing could range from elevation of privilege to information disclosure. Threat modeling, a text that explores what an adversary might attain by exploiting a flaw defines the following threat categories:

  • Spoofing identity
  • Tampering with data (also called integrity threats)
  • Repudiation
  • Information disclosure
  • Denial of service
  • Elevation of privilege

Patch management ensures that correct code replaces incorrect code. However, it is not the only way to reduce risk. The patch management process also includes mitigation techniques that are not actual patches but include additional procedures to protect networks if the patch is not available, or if admins cannot apply it to a network, or if there are other reasons that preclude applying the patch.

Footnote: Swiderski, Frank and Window Snyder "Threat modeling," Redmond, WA: Microsoft Press 2004.

Click for the next excerpt in this series: What is included in a Microsoft patch?


Click for book details or get more information from Ecora.


Tags: Microsoft Windows patches and critical updatesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Microsoft Windows patches and critical updates
Troubleshooting Microsoft WSUS connectivity issues
Windows security tools for the busy desktop administrator
Why should Windows shops use Microsoft Baseline Security Analyzer?
Enhancing patch management with NAP
The 10 most common Windows security vulnerabilities
Windows security in the enterprise: Tutorials
Microsoft will release three critical patches in May
Critical patches for IE and Office released
Have my Windows patches actually been installed?
PatchLink Update 6.4

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Windows Desktop Technology - Virtualization, Virtual Infrastructure, Virtual Desktop
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts