11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

How To:Implement Patch ManagementApplies ToThis information applies to server or workstation computers that run the following:● Microsoft ® Windows ® 2000SummaryThis How To explains patch management, including how to keep single or multipleservers up to date. Additional software is not required, except for the tools availablefor download from Microsoft.Operations <strong>and</strong> security policy should adopt a patch management process. This HowTo defines the processes required to create a sound patch management system. Thepatch management process can be automated using the guidance in this How To.What You Must KnowBefore using this How To, you should be aware of the following issues <strong>and</strong>considerations.The Patch Management ProcessPatch management is a circular process <strong>and</strong> must be ongoing. The unfortunate realityabout software vulnerabilities is that, after you apply a patch today, a newvulnerability must be addressed tomorrow.Develop <strong>and</strong> automate a patch management process that includes each of thefollowing:● Detect. Use tools to scan your systems for missing security patches. The detectionshould be automated <strong>and</strong> will trigger the patch management process.● Assess. If necessary updates are not installed, determine the severity of theissue(s) addressed by the patch <strong>and</strong> the mitigating factors that may influence yourdecision. By balancing the severity of the issue <strong>and</strong> mitigating factors, you c<strong>and</strong>etermine if the vulnerabilities are a threat to your current environment.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!