Skip to main content

Framework for building a Comprehensive Enterprise Security Patch Management Program

Patch Management is an easy concept to understand, but a challenge to execute. With client-side attacks becoming prolific, implementing security updates in a timely manner is becoming even more critical to protect information systems. There are several steps necessary for effective, sustainable patch management including vendor notification tracking, risk assessment, software packaging, and deployment. The purpose of this paper is to present a patch management framework for a typical enterprise based on authoritative standards (e.g., ISO 27002 and NIST) as well as regulatory requirements (e.g., PCI DSS).

34450 (PDF, 3.40MB)

2 Jan 2014
ByMichael Hoehl
Share
All papers are copyrighted

No re-posting of papers is permitted