Home > Ask the Information Security Experts > Questions & Answers > What is an ideal patch management process for small businesses?
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

What is an ideal patch management process for small businesses?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 22 August 2007
Should patch testing be a priority for both small and large organizations? For smaller groups that just don't have the resources, are there testing steps that can be skipped or shortened?

>
EXPERT RESPONSE
I sympathize with organizations -- large and small -- when it comes to patch management. It can be a time-consuming and resource-hungry task. The sheer number of Microsoft patches alone makes it cost-prohibitive to test all of them prior to implementation. Let's look at how a smaller organization can streamline the process.

Firstly, consider the patch management process. It starts with scanning systems for missing security patches. Thankfully, the task is now mainly an automated one. Next comes assessing whether the issue that a particular patch addresses is actually a threat to your current environment. Making that kind of decision is a lot easier if you have a system inventory that prioritizes all of your machines. Developing a business profile for each application will help enormously in assessing system importance, allowable downtime periods and vulnerability risk levels. Profiles should list expectations from the IT infrastructure, as well as end users. Such requirements can help to prioritize your efforts. Vendor-reported criticism is another key input for calculating a patch's significance. It's important to be aware of known exploits that use a given vulnerability as an attack vector.

But do remember that patches are not mandatory. The threat posed by a particular flaw may be within your risk tolerance, while some patches won't be relevant to your system and won't need to be tested or installed.

Once you have decided that a patch needs to be deployed, it should be prioritized as either a normal or emergency change. Emergency patches should be implemented immediately, while less urgent patches can be tested and deployed when time is available. Unfortunately, when it comes to the actual testing process, there aren't really any shortcuts. Testing is required because patches can overwrite working drivers, disrupt existing software and change services or functions on which your system relies.

Larger organizations can use a virtualized IT infrastructure to provide test environments, cutting ownership costs and implementation time. Test computers are another luxury, but they may be unavailable to administrators of smaller networks. If you don't have that privilege, you should at least test each patch on your own PC. Every problem you see on your own system is one less problem that you will hear about from each of your users. Be sure to have a rollback and restore plan in place though! It is also important to frequent the relevant Internet discussion news groups to find out others' experiences with a particular patch.

By completing a patch test, you can ensure a predictable rollout when it is deployed. Unfortunately, you cannot batch-test patches; if testing produces an unsatisfactory result, you must identify the exact cause of the problem before going any further. If you have installed several patches at once, finding the root of the issue will be tricky. Production rollouts can be used as an additional part of the testing process, though, if they are done in stages. The initial rollout should be to less critical systems, and if the patches perform as expected, continue with the rollout until all systems are updated.

Finally, document your decisions to install or reject specific patches so that you can provide assurance that vulnerabilities have been identified and appropriate patches have been installed. Your security policy should define your organization's stance on patch prioritization, testing and deployment.

More information:

  • Michael Cobb explains how to install the most current Microsoft patches and critical updates in one go.
  • So you push critical Windows patches once a month. But what about Acrobat Reader, QuickTime and your other third-party applications?


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Threat Management
    Network security basics: How to prevent common attacks
    Future security threats: Enterprise attacks of 2009
    Cybercrime reports: Security not broken, but breaking at the seams
    Data losses set to soar, KPMG predicts
    Screencast: How to gather host-level data with Network Miner
    Appliance provides network access protection on school campus
    Market Harborough Building Society finds way to monitor users' network traffic
    'Phlashing' attacks
    How to identify network attacks proactively
    Stopping spam brings additional security benefits for cable company

    Security Policies and Awareness
    Security is a people business, don't forget it
    Appliance provides network access protection on school campus
    How to prevent clickjacking attacks with security policy, not technology
    Privacy, data protection must be built into system design, says ICO
    Can policy thwart disgruntled employee data leaks?
    Setting up a remote access security policy
    Security policies often ignored, non-existent, survey finds
    Information Commissioner turns up the heat on data breach culprits
    DLP useless when companies fail to classify data
    Finance sector poor at achieving outsourcing success

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Centre for the Protection of National Infrastructure  (SearchSecurityUK.com)
    Serious Organized Crime Agency  (SearchSecurityUK.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts