Patch management and vulnerability management work together to help protect an organization against emerging threats. Bugs and security vulnerabilities are routinely discovered in operating systems and applications. As they are discovered, vendors write and test patches to remove the vulnerability. Patch management ensures that appropriate patches are applied and vulnerability management helps verify that systems are not vulnerable to known threats. Patch is a blanket term for any type of code written to correct a bug or vulnerability or improve the performance of existing software. The software can be either an operating system or an application. Patches are sometimes referred to as updates, quick fixes, and hot fixes. In the context of security, the patches that administrators are primarily concern with are patches that affect the vulnerability of a system. These are often referred to as security patches. Service packs are collections of patches that bring a system up-to-date with current patches. Even though vendors regularly write and release patches, these patches are useful only if they are applied. This may seem obvious, but many security incidents could have been completely avoided if systems were patched. An effective patch management program ensures that systems are kept up-to-date with current patches. These are the common steps within an effective patch management program: Evaluate patches: When patches are released, administrators evaluate the patch to determine if it applies to their systems. Test patches: Whenever possible, patches are tested on an isolated system to determine if they have any unwanted side effects. The worst case scenario is that a system will no longer start after a patch is applied. Approve the patches: Once patches have been tested and are determined to be safe, they are approved for deployment. Deploy the patches: After testing and approval, patches are deployed to systems. Many organizations use automated methods to deploy the patches. Verify that patches are deployed: After patches are deployed, systems are regularly audited and tested to ensure that they are patched. (Stewart et al., 2004) 5. Capacity Management The use of resources should be monitored, tuned and projections made of future capacity requirements to ensure the required system performance. Capacity requirements should be identified, taking into account the business criticality of the concerned system. System tuning and monitoring should be applied to ensure and, where Lebanese National Security Policy Guidelines v1.7 Page 45 |

Select target paragraph3