|
|
|
|
Patches are now a major part of any system administrator's life - but what is the most effective way to keep network security up to date without it becoming a full-time job? Once you know the who, what and where of your systems, you'll be in a position to start assessing patches as they become available. Does the patch affect any of your computers? A buffer overrun in SNMP may be very serious, but only if SNMP is in use: it may be quicker, easier and more effective to make sure that you have disabled the service. Microsoft is finally moving to a model where services default to off when installed, but most of us are still running systems with unused yet active components. Locking down is cheaper and more effective than fixing up.
Controlled testing This process would seem ideal for patch management software, and there are many packages that promise to help. However, to date the situation is overly complex: Microsoft itself has around eight different patch management tools, not all of which agree with each other. The company is working towards integrating these tools into two or three main applications, and to further integrate these into its main system management software. But for now, patch managers have to consider Windows Update -- where the clients themselves detect and install patches -- alongside the Baseline Security Analyzer, Office Update, the Office Update Inventory Tool, and the Software Update Service (SUS) -- which lets managers check and control patch deployment by server. Lately, Microsoft has integrated SUS with its System Management Server 2003, which can automate patch roll-out, make patches mandatory after a specified period, and report on which users have been patched and which remain untouched. Outside Microsoft, the patch management industry is serviced by a small group of companies. The tools they provide cover much more than just the Windows environment -- every large application and operating system needs similar care -- but none as yet is capable of coping with everything. Companies to investigate include BigFix, Ecora, Kintana, Novadigm, Shavlik Technologies, Patchlink and On Technology, and always consult your application and OS vendors for recommendations.
A serious business
|
||||||
|
|
|







