Talk With an Expert

Framework for building a Comprehensive Enterprise Security Patch Management Program

Framework for building a Comprehensive Enterprise Security Patch Management Program (PDF, 3.42MB)Published: 02 Jan, 2014
Created by
Michael Hoehl

Patch Management is an easy concept to understand, but a challenge to execute. With client-side attacks becoming prolific, implementing security updates in a timely manner is becoming even more critical to protect information systems. There are several steps necessary for effective, sustainable patch management including vendor notification tracking, risk assessment, software packaging, and deployment. The purpose of this paper is to present a patch management framework for a typical enterprise based on authoritative standards (e.g., ISO 27002 and NIST) as well as regulatory requirements (e.g., PCI DSS).