Editorial: Time to apply a patch

A renewed debate about patch management has highlighted a flaw in federal officials' views on information security.

The General Accounting Office raised the issue in a report released last week. According to GAO auditors, more than half of the 24 agencies surveyed said they lack the staff and money needed to keep up with the security flaws that have been discovered in commercial software.

Major software vendors often publicize flaws soon after they are discovered and create the necessary software patches, but it is up to customers to track the list of vulnerabilities and download, test and apply the patches.

As such, patch management is not a solution that can be bought but rather a discipline that must be learned. To date, the federal government has been content to rely on the good intentions of individual agencies to take the initiative in installing patches. GAO's study shows that that approach has not been effective, and history suggests it will never succeed.

In 2001, the General Services Administration created a patch management service to which agencies could subscribe. But the service, later transferred to the Homeland Security Department, was cancelled earlier this year because so few agencies had enrolled.

Although it was groundbreaking in 2001, the program was no longer necessary because major software vendors were offering their own, better services, DHS officials said at the time.

Yet the fact remains that many agencies, despite their best intentions, do not take advantage of the services and therefore continue to be hit by worms and viruses long after the necessary patches have been available. With the onslaught showing no sign of abating, it's time for Bush administration officials to force the issue.

One option is for DHS to re-establish a central patch-management service, but with two major differences. First, it would be based on commercially available solutions, with DHS serving primarily as a services broker. Second, although subscriptions would not be mandatory, agencies would be required to "opt out" by demonstrating they have their own system in place.

Taking such a heavy-handed approach would not be politically popular among agencies, but leaving government systems vulnerable when solutions are available should no longer be seen as politically viable.

The Fed 100

Read the profiles of all this year's winners.

Featured

  • Then-presidential candidate Donald Trump at a 2016 campaign event. Image: Shutterstock

    'Buy American' order puts procurement in the spotlight

    Some IT contractors are worried that the "buy American" executive order from President Trump could squeeze key innovators out of the market.

  • OMB chief Mick Mulvaney, shown here in as a member of Congress in 2013. (Photo credit Gage Skidmore/Flickr)

    White House taps old policies for new government makeover

    New guidance from OMB advises agencies to use shared services, GWACs and federal schedules for acquisition, and to leverage IT wherever possible in restructuring plans.

  • Shutterstock image (by Everett Historical): aerial of the Pentagon.

    What DOD's next CIO will have to deal with

    It could be months before the Defense Department has a new CIO, and he or she will face a host of organizational and operational challenges from Day One

  • USAF Gen. John Hyten

    General: Cyber Command needs new platform before NSA split

    U.S. Cyber Command should be elevated to a full combatant command as soon as possible, the head of Strategic Command told Congress, but it cannot be separated from the NSA until it has its own cyber platform.

  • Image from Shutterstock.

    DLA goes virtual

    The Defense Logistics Agency is in the midst of an ambitious campaign to eliminate its IT infrastructure and transition to using exclusively shared, hosted and virtual services.

  • Fed 100 logo

    The 2017 Federal 100

    The women and men who make up this year's Fed 100 are proof positive of what one person can make possibile in federal IT. Read on to learn more about each and every winner's accomplishments.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group