Home > Ask the Security Channel Experts > Security Management Questions & Answers > How do I create a repeatable patch testing methodology?
Ask The Security Channel Expert: Questions & Answers
EMAIL THIS

How do I create a repeatable patch testing methodology?

Felicia Wetter EXPERT RESPONSE FROM: Felicia Wetter

Pose a Question
Other Security Channel Categories
Meet all Security Channel Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 26 October 2006
I am in the process of creating some kind of repeatable testing methodology that I can use as a test guide or confidence exercise to test patches before deploying them in my customers' live environments. Can you give me some tips that I can use? To what degree should I customize the methodology for each customer?

>
EXPERT RESPONSE

In my book titled Curing the Patch Management Headache, Chapter 8 is dedicated to testing. The following answer includes some excerpts from that chapter.

Some tips for testing include developing a well-defined testing process. A testing process cannot only minimize time and resources required, but also help minimize the chaotic fallout that might result if required functionality is not accounted for during the testing process, leaving critical production systems that may not operate properly after a patch is deployed.

A high level testing process includes such phases as:

  • Pre-install activities
  • Patch installation
  • Test intended purpose
  • Test primary uses
  • Test secondary uses
  • Testing patch back out
  • Approving deployment

Another tip for testing includes creating a Release Schedule that is based on the Security Priority given to each patch. For example, a patch with a Critical Priority should be implemented within 48 hours with a maximum timeframe of within two weeks. While a Low Priority patch could have a recommended timeframe of one month with a maximum timeframe of two months. Developing a release schedule will assist in ensuring that patches are installed during a required timeframe that is achievable for the organization.

As for customizing the testing methodology, the phases listed above will apply regardless of the organization; however, the procedures may vary from customer to customer depending on their environment, the tool used to deploy the patch, the availability of a lab to conduct testing and the resources that are available to spend the time necessary on preparing the patch for deployment.

For more information on patch testing and deployment, visit our Patch Management Project Guide.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Security Patch Testing
Should hotfix testing be performed by the QA department or by support?
Testing patches virtually saves money and space
Patch testing on the cheap
Implementing third-party patches on customer systems

Security Management
Hardening Linux as part of your client's network security policy
Implementing wireless LAN security policies for mobile users
Should hotfix testing be performed by the QA department or by support?
Complying with the Federal Information Security Management Act (FISMA)
Automated patch management for SMB customers
Understanding ISO 27001 and ISO 17799
Maintaining HIPAA compliance
Creating security policies for an enterprise customer
Implementing third-party patches on customer systems
Patch management system post-deployment considerations for VARs and consultants

Patch Management
Top five security service provider tips of 2007
The true cost of offering patch management services
Microsoft WSUS deployment guide
Antivirus software patch management
Should hotfix testing be performed by the QA department or by support?
Automated patch management for SMB customers
Report: Oracle security is inferior to Microsoft's
Fixing patch mishaps in Windows
Post-patch troubleshooting: Auditing revision levels
WSUS vs. SMS: Choosing a Windows patch management tool

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts