{"id":11973,"date":"2017-09-06T11:23:20","date_gmt":"2017-09-06T11:23:20","guid":{"rendered":"https:\/\/www.process.st\/templates\/patch-management\/"},"modified":"2024-02-28T20:45:07","modified_gmt":"2024-02-28T20:45:07","slug":"patch-management","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/patch-management\/","title":{"rendered":"Patch Management"},"content":{"rendered":"<section id=\"introduction\">\n<h2> Introduction: <\/h2>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/nCJcLdhyfry_imSXiS9MIA.png\" alt=\"Introduction:\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/nCJcLdhyfry_imSXiS9MIA.png\" \/> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>Patch management is a careful process. It'd be reckless to deploy untested patches across your whole organization, so it's often done with a test group beforehand.<\/p>\n<p>A vulnerability scanner will highlight the need for patching automatically, but the reporting and deploying needs human intervention.<\/p>\n<p>In this process, you'll be able to structure your patch testing and deployment in a way that reduces the risk of error. It can also link into our scheduled maintenance process, so you can issue notifications of any expected disruptions.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"gather-and-consolidate-inventory-data-on-every-system\">\n<h2> Gather and consolidate inventory data on every system <\/h2>\n<div class=\"text-content\">\n<p>Although this information can be collected manually, ideally an automated tool linked to a database should be used.<\/p>\n<\/p><\/div>\n<div class=\"multi-select-content form-field-content\">\n<ul class=\"items\">\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       1\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Hostname\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       2\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Location\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       3\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      IP address\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       4\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      MAC address\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       5\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Operating system\n    <\/div>\n<\/li>\n<li class=\"item\">\n<div class=\"step-number-container\">\n<div class=\"step-number\">\n       6\n     <\/div>\n<\/p><\/div>\n<div class=\"step-checkbox-container\">\n<div class=\"step-checkbox\"><\/div>\n<\/p><\/div>\n<div class=\"item-name-static\">\n      Current revision level\n    <\/div>\n<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"understand-the-consequences-of-making-changes\">\n<h2> Understand the consequences of making changes <\/h2>\n<div class=\"text-content\">\n<p>Make sure that the consequences of making changes to a system are fully understood and in any event, only implement changes one or two at a time and only on test systems first.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"scan-for-vulnerabilities\">\n<h2> Scan for vulnerabilities <\/h2>\n<div class=\"text-content\">\n<p>You can use a vulnerability scanning tool like <a href=\"https:\/\/www.tenable.com\/products\/nessus\/select-your-operating-system\" rel=\"nofollow noopener\" target=\"_blank\">Nessus <\/a>to manage this step.<\/p>\n<\/p><\/div>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/mPHKKm-nZ9PVjOQBc59ArA.png\" alt=\"Scan for vulnerabilities\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/mPHKKm-nZ9PVjOQBc59ArA.png\" \/> <\/a><br \/>\n  <\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>Depending on the importance of the systems and the priority of the vulnerabilities, scanning helps you decide which patches to apply where.<\/p>\n<p>Store your scan report in the widget below to keep track of it.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"create-a-full-backup-of-all-data-and-server-configuration-information\">\n<h2> Create a full backup of all data and server configuration information <\/h2>\n<div class=\"text-content\">\n<p>Exactly how you create a backup of server config data varies based on the kind of server you're running. Below you'll find <strong>documentation for common options<\/strong>:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/unified_computing\/ucs\/sw\/cli\/config\/guide\/2-2\/b_UCSM_CLI_Configuration_Guide_2_2\/b_UCSM_CLI_Configuration_Guide_2_2_chapter_0101000.html\" rel=\"nofollow noopener\" target=\"_blank\">Cisco Servers<\/a><\/li>\n<li><a href=\"https:\/\/onlinehelp.tableau.com\/current\/guides\/everybody-install\/en-us\/everybody_admin_backup.htm\" rel=\"nofollow noopener\" target=\"_blank\">Tableau Servers<\/a><\/li>\n<li><a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/6.6.3\/Admin\/Backupconfigurations\" rel=\"nofollow noopener\" target=\"_blank\">Splunk Servers<\/a><\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/en-us\/help\/883619\/how-to-import-and-to-export-ias-configuration-information-from-one-win\" rel=\"nofollow noopener\" target=\"_blank\">Windows Servers<\/a><\/li>\n<li><a href=\"https:\/\/blogs.msdn.microsoft.com\/john_daskalakis\/2014\/10\/27\/script-to-export-the-configuration-of-sql-server\/\" rel=\"nofollow noopener\" target=\"_blank\">SQL Servers<\/a><\/li>\n<li><a href=\"https:\/\/www.ibm.com\/support\/knowledgecenter\/SSEQVQ_8.1.0\/srv.reference\/r_cmd_devconfig_backup.html\" rel=\"nofollow noopener\" target=\"_blank\">IBM Servers<\/a><\/li>\n<li><a href=\"https:\/\/wiki.contribs.org\/Backup_server_config\" rel=\"nofollow noopener\" target=\"_blank\">SME Servers<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"deploy-patches-to-the-test-group\">\n<h2> Deploy patches to the test group <\/h2>\n<div class=\"text-content\">\n<p>A test group is a limited number of users who receive patches before anybody else. This way, if anything goes wrong the <strong>damage is limited to just the test users<\/strong>. Test users should be technicians, or at least staff familiar with reporting bugs and finding errors.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"document-test-results-and-present-for-review-by-internal-system-owners\">\n<h2> Document test results and present for review by internal system owners <\/h2>\n<div class=\"text-content\">\n<p>Using the logs from your test group, <strong>create a summary of the patch results<\/strong>.<\/p>\n<p>Check here (<a href=\"http:\/\/eskonr.com\/2011\/10\/sccm-monthly-patch-statistics-reports-to-the-management-in-a-simplified-manner\/\" rel=\"nofollow noopener\" target=\"_blank\">part one<\/a>, <a href=\"http:\/\/eskonr.com\/2010\/03\/monthly-patch-statistics-reports-to-show-up-to-the-management-in-a-simplified-manner\/\" rel=\"nofollow noopener\" target=\"_blank\">part two<\/a>) for a guide on generating a report for SCCM systems. Alternatively, <a href=\"https:\/\/support.symantec.com\/en_US\/article.HOWTO3124.html#6.Reporting|outline\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a> is a guide for managing configuring with Symantec.<\/p>\n<p>Attach the summary below.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"notify-internal-system-owners-of-any-downtime-or-alerts-they-will-experience\">\n<h2> Notify internal system owners of any downtime or alerts they will experience <\/h2>\n<div class=\"text-content\">\n<p>Use the <a href=\"https:\/\/www.process.st\/templates\/scheduled-maintenance-notification\/\" rel=\"nofollow noopener\" target=\"_blank\">scheduled maintenance notification<\/a> process to make this easier by generating a report.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"roll-out-patch-enterprisewide\">\n<h2> Roll out patch enterprise-wide <\/h2>\n<div class=\"text-content\">\n<p>The best time to schedule patching is <strong>the early hours of the morning<\/strong>. Microsoft <a href=\"http:\/\/techgenix.com\/patch-or-not-weighing-risks-immediate-updating\/\" rel=\"nofollow noopener\" target=\"_blank\">schedules updates for Tuesdays<\/a> and even though there's an (unscheduled) &quot;Recall Thursday&quot;, it's best to make patching a predictable and regular event.<\/p>\n<p>Make sure to <strong>monitor the systems closely after roll-out<\/strong>.<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"sources\">\n<h2> Sources: <\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.sans.org\/\" rel=\"nofollow noopener\" target=\"_blank\">SANS<\/a> - <a href=\"https:\/\/www.sans.org\/reading-room\/whitepapers\/bestprac\/practical-methodology-implementing-patch-management-process-1206\" rel=\"nofollow noopener\" target=\"_blank\">Practical Methodology for Implementing a Patch Management Process<\/a><\/li>\n<li><a href=\"http:\/\/techgenix.com\/\" rel=\"nofollow noopener\" target=\"_blank\">TechGenix<\/a> - <a href=\"http:\/\/techgenix.com\/patch-or-not-weighing-risks-immediate-updating\/\" rel=\"nofollow noopener\" target=\"_blank\">Patch or Not? Weighing the Risks of Immediate Updating<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"related-checklists\">\n<h2> Related checklists: <\/h2>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Introduction: Patch management is a careful process. It'd be reckless to deploy untested patches across your whole organization, so it's often done with a test group beforehand. A vulnerability scanner will highlight the need for patching automatically, but the reporting and deploying needs human intervention. In this process, you'll be able to structure your patch [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":11974,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"","cover_icon_url":"","tasks_count":"11","template_description":"How to prevent downtime while updating your company systems.","template_id":"sN8HFu7Hq81qxSyBrH5FVw","task_0":"Introduction:","task_slug_0":"introduction","task_1":"Gather and consolidate inventory data on every system","task_slug_1":"gather-and-consolidate-inventory-data-on-every-system","task_2":"Understand the consequences of making changes","task_slug_2":"understand-the-consequences-of-making-changes","task_3":"Scan for vulnerabilities","task_slug_3":"scan-for-vulnerabilities","task_4":"Create a full backup of all data and server configuration information","task_slug_4":"create-a-full-backup-of-all-data-and-server-configuration-information","task_5":"Deploy patches to the test group","task_slug_5":"deploy-patches-to-the-test-group","task_6":"Document test results and present for review by internal system owners","task_slug_6":"document-test-results-and-present-for-review-by-internal-system-owners","task_7":"Notify internal system owners of any downtime or alerts they will experience","task_slug_7":"notify-internal-system-owners-of-any-downtime-or-alerts-they-will-experience","task_8":"Roll out patch enterprise-wide","task_slug_8":"roll-out-patch-enterprisewide","task_9":"Sources:","task_slug_9":"sources","task_10":"Related checklists:","task_slug_10":"related-checklists","task_11":"","task_slug_11":"","task_12":"","task_slug_12":"","task_13":"","task_slug_13":"","task_14":"","task_slug_14":"","task_15":"","task_slug_15":"","task_16":"","task_slug_16":"","task_17":"","task_slug_17":"","task_18":"","task_slug_18":"","task_19":"","task_slug_19":"","task_20":"","task_slug_20":"","task_21":"","task_slug_21":"","task_22":"","task_slug_22":"","task_23":"","task_slug_23":"","task_24":"","task_slug_24":"","task_25":"","task_slug_25":"","task_26":"","task_slug_26":"","task_27":"","task_slug_27":"","task_28":"","task_slug_28":"","task_29":"","task_slug_29":"","task_30":"","task_slug_30":"","task_31":"","task_slug_31":"","task_32":"","task_slug_32":"","task_33":"","task_slug_33":"","task_34":"","task_slug_34":"","task_35":"","task_slug_35":"","task_36":"","task_slug_36":"","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[7,1],"tags":[],"class_list":["post-11973","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-miscellaneous","category-uncategorized"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/11973","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=11973"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/11973\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media\/11974"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=11973"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=11973"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=11973"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}