![]() |
![]() |
|
October 09, 2003Microsoft Security Patch ManagementEveryone likes to knock MS for security patches. Solas had a good rant on it today. I think we need to remember that there are improved ways to deal with security in Windows environments, its just that not many people know about them. Microsoft released a data sheet today about their Systems Management Server 2003 product and how it deals with Security Patch Management. You can improve your security posture of your Windows environment through increased vulnerability awareness and reliable targeted delivery of updates. (Their words, not mine) If you want to try to understand what SMS is about, you might wanna read this. You might find it useful when exploring what tools to use to manage security for your Windows platforms. Posted by SilverStr at October 9, 2003 04:32 PM | TrackBackComments
Isn't SMS the thing that was broken by recent updates, right around the time of the blaster worm? I could be wrong but I seem to remember something about that. Posted by: Arcterex at October 10, 2003 01:24 PMThere have been some issues with SMS, but I think the issue you are referring to was the break down of HFNetChk from Shavlik during the worm outbreak. Many people prefer it to SMS, and like working with Shavlik since they wrote the scanning engine underneith the Microsoft Baseline Security Analyzer (MBSA). I don't honestly know if SMS died during the worm outbreak. My point was that there are tools out there for Windows environments that can mitigate the risks and exposure duing critical patch times. Having to only download a patch once to the network is much more effective than saturating the bandwidth when 100's of machines need the same patch within hours. (outside of proxy cache that can save time) Posted by: SilverStr at October 11, 2003 01:39 PM |
![]() ![]()
My 5 Favorite Books
Writing Secure Code
Secure Programming Cookbook Security Engineering Secure Coding Principles & Practice Inside the Security Mind ![]()
My 5 Favorite Papers
Smashing the Stack
Penetration Studies Covert Channel Analysis of Trusted Systems DoD Trusted Computer System Evaluation Criteria NSA Security Recommendation Guides ![]()
Archives
December 2005
November 2005 October 2005 September 2005 August 2005 July 2005 June 2005 May 2005 April 2005 March 2005 February 2005 January 2005 December 2004 November 2004 October 2004 September 2004 August 2004 July 2004 June 2004 May 2004 April 2004 March 2004 February 2004 January 2004 December 2003 November 2003 October 2003 September 2003 August 2003 July 2003 June 2003 May 2003 April 2003 March 2003 February 2003 January 2003 December 2002 November 2002 October 2002 September 2002 August 2002 July 2002 ![]() |
|