Feeds

Of Windows patch management

Stay in control of updates

Intelligent flash storage arrays

If there's a new patch available for Windows, you probably want it applied as soon as possible. It is unlikely, though, that you will want to roll out that update to users automatically because whether they contain new features, fix bugs or plug security holes, patches can break applications.

It makes more sense for IT to use Windows Server Update Services to deploy updates, test them and control how they are installed, rather than allowing users to download and install automatically, with all the potential for breakage that follows.

Ultimately, automating patching while retaining control is the goal.

Advance warning

Microsoft updates arrive predictably on Patch Tuesday (the second Tuesday of every month), which means you can plan ahead for testing. You can get advance notice by subscribing to the security bulletin, which comes out three business days before with details of the updates – think of it as Threatening Thursday.

Attackers also get details of the vulnerabilities that have been patched so there's no time for delay before the first attempts to circumvent the patch. Microsoft also occasionally releases important patches on other days besides Tuesday, and these too tend to require urgent attention.

If yours is an industry that is regulated or your organisation has to deal with compliance issues, you need a patching schedule to stay compliant.

Protecting the weak

Microsoft IT must keep 98 per cent of desktops up to date on patches. It is the IT department that has to cope with the patches, not the product teams, so the company has to figure out the impact on internal applications before it rolls them out.

Updates are not universally applicable, so you need to audit to see which systems will need to be patched for given vulnerabilities.

Not all patches are urgent either. New product features tend to be issued in the form of feature and service packs rather than patches but patches can include performance improvements.

In any case, they all need to be evaluated. And you have to take a view between being able to take longer to test less urgent updates and the impact on productivity if users have to reboot for a second batch of updates each month.

Anti-virus signature updates don't need testing and approval, especially for enterprise-grade anti-virus systems that update their definitions three times a day.

Dedicated enterprise anti-virus systems usually do this automatically. If you are managing Forefront Endpoint Protection through System Center Configuration Manager, the 2012 release will let you choose specific languages of definitions to approve automatically.

Race against time

Occasionally Microsoft deems patches so critical that it pushes them out sooner. Because they address significant problems, you need to evaluate them even though the time has not been allocated in advance.

Microsoft's security bulletin and third-party services will alert you to these unscheduled patches (and you may find the third-party advice on the impact of patches worth paying for).

Critical as it may be to deploy patches, a strategy for evaluating them is even more important. You may be tempted to rush out an urgent patch but you need to know if it will disrupt your business applications. The best advice is to keep software audits current so you know which systems will be affected.

Testing, testing

There are several ways to test patches. You can use test systems with scripts that cover system and application functionality or do it more informally by rolling patches out to a subset of users. If that lucky group is the IT team, make sure they have a good mix of production apps and the scripts to run through common tasks.

Larger businesses may want to stagger deployment to reduce the load on the network – and on the support team if updates cause problems.

You need to track which updates have been applied successfully. Even a small business needs a change management system to record patches and updates.

As well as dealing with Microsoft applications you will need a patching strategy for third-party apps and network devices. Third-party tools like App-DNA’s AppTitude and ChangeBase’s AOK help you track updates for multiple products, as well as providing guidance on what applications will be affected by Microsoft updates.

They won't lift the burden of understanding monthly updates, but at least you don’t have to approach the problem from scratch every time. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
PEAK APPLE: iOS 8 is least popular Cupertino mobile OS in all of HUMAN HISTORY
'Nerd release' finally staggers past 50 per cent adoption
Microsoft to bake Skype into IE, without plugins
Redmond thinks the Object Real-Time Communications API for WebRTC is ready to roll
Microsoft promises Windows 10 will mean two-factor auth for all
Sneak peek at security features Redmond's baking into new OS
Mozilla: Spidermonkey ATE Apple's JavaScriptCore, THRASHED Google V8
Moz man claims the win on rivals' own benchmarks
Yes, Virginia, there IS a W3C HTML5 standard – as of now, that is
You asked for it! You begged for it! Then you gave up! And now it's HERE!
FTDI yanks chip-bricking driver from Windows Update, vows to fight on
Next driver to battle fake chips with 'non-invasive' methods
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
Ubuntu 14.10 tries pulling a Steve Ballmer on cloudy offerings
Oi, Windows, centOS and openSUSE – behave, we're all friends here
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Website security in corporate America
Find out how you rank among other IT managers testing your website's vulnerabilities.