CERT
 
OCTAVE Articles & Reports CSIRT Development Information Vulnerability Notes Courses US-CERT cylab
 
   
April 1, 2001:
Larry Rogers on Applying Security Patches

Did you know that 95% of all network intrusions could be avoided by keeping your computer systems up to date with patches? Easier said than done.

Applying patches is often a hard and time-consuming task, especially when you must do so from the system's console. In addition, application vendors don't always tell you whether their products will continue to work after you install a patch. Since applications are often the lifeblood of business, security is critical, though it's sometimes sacrificed to keep the business running. Ultimately, the business will suffer.

We strongly suggest that you patch whenever possible.

When you're not sure if you can apply a patch without repercussions, contact your vendor and ask. The more customers who ask these questions, the more likely the vendors will make their products work on patched systemsand publicize their efforts. You voted with your dollars when you bought your systems and applications, now vote with your telephone and email to keep 'em running securely!

Larry Rogers teaches courses on security practices for system administrators as well as performing system administration himself. His professional interests include analyzing system and network vulnerabilities, defining ways to administer systems in a secure fashion, and identifying software tools and techniques for creating new systems being deployed on the Internet.


 
Disclaimers and copyright information | Last updated February 27, 2006