Patch management and vulnerability management work together to help protect an
organization against emerging threats. Bugs and security vulnerabilities are routinely
discovered in operating systems and applications. As they are discovered, vendors write and
test patches to remove the vulnerability. Patch management ensures that appropriate patches
are applied and vulnerability management helps verify that systems are not vulnerable to
known threats.
Patch is a blanket term for any type of code written to correct a bug or vulnerability or improve
the performance of existing software. The software can be either an operating system or an
application. Patches are sometimes referred to as updates, quick fixes, and hot fixes. In the
context of security, the patches that administrators are primarily concern with are patches that
affect the vulnerability of a system. These are often referred to as security patches. Service
packs are collections of patches that bring a system up-to-date with current patches.
Even though vendors regularly write and release patches, these patches are useful only if they
are applied. This may seem obvious, but many security incidents could have been completely
avoided if systems were patched. An effective patch management program ensures that
systems are kept up-to-date with current patches. These are the common steps within an
effective patch management program:
Evaluate patches: When patches are released, administrators evaluate the patch to
determine if it applies to their systems.
Test patches: Whenever possible, patches are tested on an isolated system to
determine if they have any unwanted side effects. The worst case scenario is that a
system will no longer start after a patch is applied.
Approve the patches: Once patches have been tested and are determined to be safe,
they are approved for deployment.
Deploy the patches: After testing and approval, patches are deployed to systems. Many
organizations use automated methods to deploy the patches.
Verify that patches are deployed: After patches are deployed, systems are regularly
audited and tested to ensure that they are patched.
(Stewart et al., 2004)
5. Capacity Management
The use of resources should be monitored, tuned and projections made of future capacity
requirements to ensure the required system performance.
Capacity requirements should be identified, taking into account the business criticality of the
concerned system. System tuning and monitoring should be applied to ensure and, where
Lebanese National Security Policy Guidelines v1.7
Page
45 |