Survey: Most Oracle shops don't mandate use of security patches
Computerworld - A lack of corporate mandates to quickly install Oracle Corp.'s security patches may be leaving many Oracle database installations exposed to vulnerabilities for extended periods of time, according to survey results released last week.
In a pair of online surveys jointly conducted by the Independent Oracle Users Group (IOUG) and Oracle between May and August last year, only 26% of the 150-plus respondents said their companies require the vendor's quarterly patch updates to be applied on all systems.
Another 6% said they are required to install the patches on critical systems only, the IOUG and Oracle reported. Meanwhile, 30% said their companies don't have any policies for Oracle's patches, while 32% said database administrators have to do risk or cost-benefit analyses to justify the patching of databases.
In addition, the survey results showed that most of the respondents aren't keeping up with Oracle's patch releases. Only 30% said they typically install patches before the company issues its next batch of fixes, according to the report. Twenty-five percent said they were one update cycle behind, while 26% said they were off by two to four cycles. Another 11% said they hadn't installed any of Oracle's patches.
Oracle typically issues dozens of patches across its entire product suite as part of the quarterly updates.
Patching databases in particular is a complex task that can require months of labor and significant system downtime. But the fact that many companies haven't even set policies for dealing with Oracle's patches is startling, especially since databases are such important corporate assets, said Ian Abramson, the IOUG's president.
"I think the feeling in those organizations is that since databases are a little more isolated than the desktop, there's less of a [security] concern," said Abramson, director of the enterprise data group at Thoughtcorp, an IT services firm in Toronto.
Oracle didn't respond to a request for comment. But in a blog posting, Eric Maurice, the company's director of software security assurance, said that Oracle and the IOUG will work together to promote broader adoption of policies for deploying patches.
He also said that Oracle will "explore ways" to improve its patch documentation to try to make the process of testing patches easier and faster for users.
This version of the story originally appeared in Computerworld's print edition.
Read more about Security in Computerworld's Security Topic Center.
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts