Patch management best practices

Here are some recommendations from the General Accounting Office to ensure that a patch management program succeeds.

* Get senior executive support. Making senior managers aware of security risks and the need for patches is important for successfully implementing security processes and ensuring that appropriate resources are available.

* Establish standardized patch management policies, procedures and tools. A standardized approach ensures that each office within an agency deploys patches and does so in a similar manner.

* Clearly assign responsibilities and provide dedicated resources. The National Institute of Standards and Technology recommends creating a designated group whose duties would include supporting administrators in finding and fixing vulnerabilities in the organization's software.

* Create and maintain an inventory of all hardware, software, services and other technologies in use throughout the agency. The inventory will help managers identify systems that are vulnerable and require remediation.

* Identify vulnerabilities and appropriate patches. This involves proactively monitoring for new vulnerabilities and patches for all software identified in the systems inventory. Various tools and services are available to assist in this process.

* Conduct risk assessments. When a vulnerability is discovered and a related patch is released, officials must consider how important the affected system is to network operations, how critical the vulnerability is and whether or not applying the patch might have unwanted side effects. Some patches can cause unexpected disruption to systems, so agencies may choose not to apply every patch immediately.

* Test each patch. Evaluate individual patches in various system configurations in a test environment before installing them agencywide to avoid any negative impact on the network.

* Distribute patches effectively. Organizations can deploy patches to systems manually or by using an automated tool. However, keep in mind that if remote users are not connected to the network when a patch is deployed, agency systems may still be vulnerable from the remote user's unpatched system.

* Continue monitoring the network for vulnerabilities. Scan networks on a regular basis to assess their overall health and if patches have been effectively applied.

Featured

  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.