Feeds

Cisco hops onto patching treadmill

Network giant wheels out bi-annual IOS update cycle

Top 5 reasons to deploy VMware with Tegile

Cisco has taken a leaf out of Microsoft's book by adopting a regular patch release cycle. However, the change will apply only to security bugs involving its core IOS software and not all its products.

Starting on 26 March, Cisco will release bundles of IOS security advisories on the fourth Wednesday of March and September in each calendar year.

The networking giant gave itself room for manoeuvre by reserving the right to publish out of sequence patches in cases where serious security vulnerabilities are publically disclosed or for bugs which become the target of active exploitation.

Cisco will continue to issue security advisories for products other than IOS, its network operating system that features on a wide range of Cisco switches and routers, as and when needed. For example, future security updates to VoIP kit will be published without reference to any regular patch release schedule, according to Cisco's pre-existing standard disclosure policy.

As with Microsoft and Oracle before it, Cisco explained the change is the result of customer requests for greater predictability over the timing of patch releases. Its patch cycle is less frequent than Oracle's quarterly release schedule and Microsoft's infamous Patch Tuesday updates, partly because network security updates are often trickier to test and roll out than application or operating system patches.

The format of Cisco's advisory will remain unchanged, as explained here. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
NSA SOURCE CODE LEAK: Information slurp tools to appear online
Now you can run your own intelligence agency
Azure TITSUP caused by INFINITE LOOP
Fat fingered geo-block kept Aussies in the dark
NASA launches new climate model at SC14
75 days of supercomputing later ...
Yahoo! blames! MONSTER! email! OUTAGE! on! CUT! CABLE! bungle!
Weekend woe for BT as telco struggles to restore service
Cloud unicorns are extinct so DiData cloud mess was YOUR fault
Applications need to be built to handle TITSUP incidents
BOFH: WHERE did this 'fax-enabled' printer UPGRADE come from?
Don't worry about that cable, it's part of the config
Stop the IoT revolution! We need to figure out packet sizes first
Researchers test 802.15.4 and find we know nuh-think! about large scale sensor network ops
SanDisk vows: We'll have a 16TB SSD WHOPPER by 2016
Flash WORM has a serious use for archived photos and videos
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
The total economic impact of Druva inSync
Examining the ROI enterprises may realize by implementing inSync, as they look to improve backup and recovery of endpoint data in a cost-effective manner.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Business security measures using SSL
Examines the major types of threats to information security that businesses face today and the techniques for mitigating those threats.