Feeds

Cisco hops onto patching treadmill

Network giant wheels out bi-annual IOS update cycle

Internet Security Threat Report 2014

Cisco has taken a leaf out of Microsoft's book by adopting a regular patch release cycle. However, the change will apply only to security bugs involving its core IOS software and not all its products.

Starting on 26 March, Cisco will release bundles of IOS security advisories on the fourth Wednesday of March and September in each calendar year.

The networking giant gave itself room for manoeuvre by reserving the right to publish out of sequence patches in cases where serious security vulnerabilities are publically disclosed or for bugs which become the target of active exploitation.

Cisco will continue to issue security advisories for products other than IOS, its network operating system that features on a wide range of Cisco switches and routers, as and when needed. For example, future security updates to VoIP kit will be published without reference to any regular patch release schedule, according to Cisco's pre-existing standard disclosure policy.

As with Microsoft and Oracle before it, Cisco explained the change is the result of customer requests for greater predictability over the timing of patch releases. Its patch cycle is less frequent than Oracle's quarterly release schedule and Microsoft's infamous Patch Tuesday updates, partly because network security updates are often trickier to test and roll out than application or operating system patches.

The format of Cisco's advisory will remain unchanged, as explained here. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Azure TITSUP caused by INFINITE LOOP
Fat fingered geo-block kept Aussies in the dark
You think the CLOUD's insecure? It's BETTER than UK.GOV's DATA CENTRES
We don't even know where some of them ARE – Maude
729 teraflops, 71,000-core Super cost just US$5,500 to build
Cloud doubters, this isn't going to be your best day
Want to STUFF Facebook with blatant ADVERTISING? Fine! But you must PAY
Pony up or push off, Zuck tells social marketeers
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
SAVE ME, NASA system builder, from my DEAD WORKSTATION
Anal-retentive hardware nerd in paws-on workstation crisis
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Managing SSL certificates with ease
The lack of operational efficiencies and compliance pitfalls associated with poor SSL certificate management, and how the right SSL certificate management tool can help.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.