Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Patching rhythm: Start a monthly patch process

November 11, 2003 12:00 PM ET

Computerworld - On the topic of security alerts and patches, Microsoft Corp. is undoubtedly the 800-pound gorilla. When the company publicized its strategy of issuing security alerts once a month (see story), I was initially dismayed, but the wisdom of the decision sank in.
Much of the frustration expressed by IT managers around the world has a lot to do with the unpredictability of security alerts. They could come at any time, and we'd have to drop what we were doing and spring into action -- at least the action of analyzing and understanding how bad the latest salvo could be. What would go through my mind was, "Is this the alert that if left unpatched could lead to 'Son of Blaster'?"
Assimilating patch alerts under the old process was like responding to earthquakes. You could be prepared, to a point, but you never knew when it would strike or how bad it would be.
Now, the security alerts are more like hurricanes. We know they're out there and when they will make landfall (the second Tuesday of the month, all year long), but we still don't know exactly how bad they will be.
Still, Microsoft's releasing security alerts on the second Tuesday of the month presents a great opportunity: the ability to plan.
Mark your calendars
Now that you know when Microsoft will issue the security alerts, it's time to schedule some recurring meetings.

  • The morning after the second Tuesday: Schedule one to two hours to analyze security alerts and do some rough prioritizing and risk analysis.
  • Same day, in the afternoon: Meet with Windows NT administrators and end-user systems administrators to discuss the alerts, their priorities, which ones are relevant, which ones are urgent, which ones can wait and which ones can safely be ignored.
  • Thursday: Windows NT administrators and end-user systems administrators begin testing systems with patch(es) installed. Also, begin work on patch-distribution plans.
  • Friday: Distribute patches to test systems. The users who are in the test program know that new patches are coming, and they'll avoid highly critical work since they know that a reboot is likely. The patches will run all day Friday and over the weekend. If you're squeamish about patching test systems on Friday, or if it takes more time to package a test distribution, wait until Monday.
    Peter H. Gergory

  • Tuesday or Wednesday: Meet to discuss testing, make decisions on how to proceed with deployment of patches to entire company.
  • Thursday: Begin deployment of patches to systems.



Jump to comments

Security

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...