Find White Papers
Home
About Us
List Your Papers
    
> Absolute Software > Proactive Patch Management

Proactive Patch Management

White Paper Published By: Absolute Software

Deploying patches in a timely fashion soon after they become available helps secure the OS and prevent the majority of data breaches. However, many computer systems are often not patched for months or not at all. While patch management can be a cumbersome task, the ability to deploy patches efficiently can save the tremendous costs of downtime and recovery from an outbreak. This whitepaper discusses the elements of a good patch management solution, conditions for patch management to be effective, and the ROI of automated patch management.



Tags : 
computrace, absolute software, it asset management, remote data delete, geolocation tracking, theft recovery, service guarantee, application integration

Absolute Software
Published:  Jan 27, 2010
Type:  White Paper
Length:  10 pages

whitepaper
Absolute Manage: Client Management
Intelligent, Automated, Cross-Platform Management of All Your Computers
Proactive Patch Management
Even the Best Software Sometimes Needs Patching 2The Reality Behind Most Virus Outbreaks 3The Patch Management Cycle 4Essential Elements of a Good Patch Management Solution 4Conditions for a Patch Management Solution To Be Effective 5The Consequences of No Patch Management 6The ROI for Automated Patch Management 7Benefits of Absolute Manage Automated Patch Management 8Conclusion 10About Absolute Software 10
www.absolute.comAbsolute Software whitepaper
Even the Best Software Sometimes Needs PatchingSoftware flaws that compromise the security of the system are often referred to as vulnerabilities. As the complexity and source code for modern operating systems has grown dramatically so has the number of vulnerabilities in the OS. The CERT Coordination Center estimates that software vulnerabilities have grown in number from 171 in 1995 to 8,064 in 20061. If past history is any indicator this number will only get bigger in the future.
900080007000se 6000itili 5000bar 4000enlu 3000V 200010000 1995 1996 1997 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007
Year Vulnerabilities1995 1711996 3451997 3111998 2621999 4172000 10902001 24372002 41292003 37842004 37802005 59902006 80642007 7236
When a vulnerability is discovered OS vendors typically release an OS patch referred to as a security update to repair the problem and prevent future security breaches due to exploitation of the vulnerability. According to the CERT Coordination Center, deploying these patches in a timely fashion soon after they become available helps secure the OS and prevent 95% of security breaches. However, many computer systems are often not patched for months or not at all. With virtually all modern workstations being attached to a local area network with Internet access, leaving them inadequately patched is not an option. 1 http://www.cert.org/stats/vulnerability_remediation.html 2
www.absolute.comAbsolute Software whitepaper
The Reality Behind Most Virus OutbreaksUnpatched computers are a major security problem because viruses often take advantage of these vulnerabilities to infect them. The 2006 Computer Security Institute/FBI Computer Crime and Security Survey reports that virus contamination continues to be the number one source of financial losses for enterprises and accounts for 30% of financial losses due to security breaches2. Even more alarming is the advent of "zero-day" exploits where an exploit is written to take advantage of the vulnerability before or within 24 hours of its discovery. Luckily zero-day exploits are the exception rather than the norm. In reality, most viruses take advantage of known vulnerabilities that have already been patched by the OS vendor but whose associated security update has yet to be deployed. For example, the Slammer virus, which reportedly took down a 911 call center, airline booking systems, and ATM machines exploited a known vulnerability that Microsoft had provided a patch for six months prior. The same was true for the now infamous Nimda worm. It took advantage of an already known and patched vulnerability that Microsoft had provided a security update for a month before. Code Red, Blaster, and MyDoom - all these viruses exploited known vulnerabilities for which there was a patch or some other known fix.
As the complexity of modern operating systems has advanced so has the technology hackers use to create viruses and worms. Often exploitation tools are posted on the Internet that allows even novice programmers such as "script kiddies", who have little or no knowledge, to create a computer virus with just a few clicks. Because of the interconnectivity of modern networks, viruses can quickly infect a significant number of computers within minutes or hours. All it takes is single person to open an email containing the virus to potentially infect all unpatched computers on an entire network.
This underscores the importance of keeping your enterprise's workstations up to date with the latest OS patches. Patches, as a preventative measure, are only useful if you deploy them before your workstations become infected. Thanks to incidents like those mention... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search