April 1, 2001:
Larry Rogers on Applying Security Patches
Did you know that 95% of all network intrusions could be avoided by keeping your computer
systems up to date with patches? Easier said than done.
Applying patches is often a hard and
time-consuming task, especially when you
must do so from the system's console. In
addition, application vendors don't always
tell you whether their products will continue
to work after you install a patch. Since
applications are often the lifeblood of
business, security is critical, though it's
sometimes sacrificed to keep the business
running. Ultimately, the business will suffer.
We strongly suggest that you patch
whenever possible.
When you're not sure if you can apply a patch without repercussions,
contact your vendor and ask. The more customers who ask these
questions, the more likely the vendors will make their products work on
patched systemsand publicize their efforts. You voted with your dollars
when you bought your systems and applications, now vote with your
telephone and email to keep 'em running securely!
Larry Rogers teaches courses on security practices for system
administrators as well as performing system administration himself. His
professional interests include analyzing system and network
vulnerabilities, defining ways to administer systems in a secure fashion,
and identifying software tools and techniques for creating new systems
being deployed on the Internet.
|