Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Patch Management on Critical Servers (Healthcare) |
|---|---|
| Date: | Tue, 09 May 2006 12:11:49 -0700 |
Chris Dalton wrote:
Some key items to remember is that testing of the patch must be done in a separate environment from production.
The test system must be at the same level as production.
Production data must not be used in testing
There must be a proper segregation of duites between those who test and those who move into production.
Chris G. Dalton C.P.A. Corporate Audit Services Capital One Financial 1-504-533-6419 phone 1-504-533-2355 fax
I'm a fan of Shavlik.... not only from the standpoint of their product..but their 'community help' posture as well. They run the patchmanagement.org listserve that discusses patch management platforms and patching issues. (Check out www.patchmanagement.org)"Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]" <sbradcpa@pacbell.net> 05/08/06 4:44 PM >>>
Honestly.. it's the process of change management that is the hard part, I think..the testing and the approval process. No matter what patch tool you chose will have it's nuances that you get used to.
Why do I like Shavlik?
Because it just shows me the patches I need in a nice format unlike WSUS which has a confusing UI.
Because it works.
Because it has additional features like 'reboot before patching', Office local install source, and will patch things beyond MS in my network.
Jim Stagg wrote:
On this topic, I'd love to hear from some of the non-WSUS Microsoft server folks are doing. I've heard a lot about BigFix, Patchlink, St. Bernard, SMS, GFI et al. Has anyone found a product that works reliably?
-- Jim Stagg, Systems Administrator
-----Original Message-----
From: Renee Peters [mailto:reneep@Northeastcollege.com] Sent: Monday, May 08, 2006 10:41 AM
To: beinm@ummhc.org; focus-ms@securityfocus.com Subject: RE: Patch Management on Critical Servers (Healthcare)
Last year, our college campus was hit with an unclassified virus. After the hours it took to manually run around and patch 1000+ computers, our upper management finally approved a WSUS server. Knock on wood, it has run beautifully, and keeps our desktops and servers patched. As far as actually getting the updates applied and rebooting, we have standard times posted that the server may be unavailable due to routine maintenance. After last year's scare, everybody seems to be OK with this slight inconvience. We aren't regulated as much as the healthcare field, but do still have standards to meet for state and federal funding. As long as the president of the college supports our practices, we don't have much to worry about.
Renee Network Manager
-----Original Message-----
From: beinm@ummhc.org [mailto:beinm@ummhc.org] Sent: Monday, May 08, 2006 8:02 AM
To: focus-ms@securityfocus.com Subject: Patch Management on Critical Servers (Healthcare)
Hello
I'm just curious to hear how people in the field have been handling patch management with critical servers. Have you setup maintenance windows? If, so how did you manage the down time? What have people been doing if the device or server has an approved FDA configuration? Are you using thing like WSUS?
Thanks,
Matthew
Security Engineer
-------------------------------------------------------------- ---------- --- -------------------------------------------------------------- ---------- ---
-------------------------------------------------------------- ------------- -------------------------------------------------------------- -------------
* Letting your vendors set your risk analysis these days? http://www.threatcode.com
--------------------------------------------------------------------------- ---------------------------------------------------------------------------
--------------------------------------------------------------------------- ---------------------------------------------------------------------------
| Previous by Date: | Re: Patch Management on Critical Servers (Healthcare), Chris Dalton |
|---|---|
| Next by Date: | Re: windows 2003 1wan 2lan => vpn to ech private lan?, Kheno vRs |
| Previous by Thread: | Re: Patch Management on Critical Servers (Healthcare), Chris Dalton |
| Next by Thread: | RE: Patch Management on Critical Servers (Healthcare), Michael Scheidell |
| Indexes: | [Date] [Thread] [Top] [All Lists] |