Home > Ask the Security Channel Experts > Security Management Questions & Answers > How do I create a repeatable patch testing methodology?
Ask The Security Channel Expert: Questions & Answers
EMAIL THIS

How do I create a repeatable patch testing methodology?

Felicia Wetter EXPERT RESPONSE FROM: Felicia Wetter

Pose a Question
Other Security Channel Categories
Meet all Security Channel Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 26 October 2006
I am in the process of creating some kind of repeatable testing methodology that I can use as a test guide or confidence exercise to test patches before deploying them in my customers' live environments. Can you give me some tips that I can use? To what degree should I customize the methodology for each customer?


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security Patch Testing
Should hotfix testing be performed by the QA department or by support?
Testing patches virtually saves money and space
Patch testing on the cheap
Implementing third-party patches on customer systems

Security Management
Hardening Linux as part of your client's network security policy
Implementing wireless LAN security policies for mobile users
Should hotfix testing be performed by the QA department or by support?
Complying with the Federal Information Security Management Act (FISMA)
Automated patch management for SMB customers
Understanding ISO 27001 and ISO 17799
Maintaining HIPAA compliance
Creating security policies for an enterprise customer
Implementing third-party patches on customer systems
Patch management system post-deployment considerations for VARs and consultants

Vulnerability and patch management
Mitigating zero-day vulnerabilities in customers' environments
Despite customer interest, channel struggles with threat management
Portcullis Systems adds HP security products to Microsoft customers
Agilex partners with HBGary to offer security forensic, assessment services
Snort vs. Microsoft Security Bulletin MS08-068
Top security tips for solutions providers
Top five security service provider tips of 2007
The true cost of offering patch management services
Microsoft WSUS deployment guide
Antivirus software patch management

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


In my book titled Curing the Patch Management Headache, Chapter 8 is dedicated to testing. The following answer includes some excerpts from that chapter.

Some tips for testing include developing a well-defined testing process. A testing process cannot only minimize time and resources required, but also help minimize the chaotic fallout that might result if required functionality is not accounted for during the testing process, leaving critical production systems that may not operate properly after a patch is deployed.

A high level testing process includes such phases as:

  • Pre-install activities
  • Patch installation
  • Test intended purpose
  • Test primary uses
  • Test secondary uses
  • Testing patch back out
  • Approving deployment

Another tip for testing includes creating a Release Schedule that is based on the Security Priority given to each patch. For example, a patch with a Critical Priority should be implemented within 48 hours with a maximum timeframe of within two weeks. While a Low Priority patch could have a recommended timeframe of one month with a maximum timeframe of two months. Developing a release schedule will assist in ensuring that patches are installed during a required timeframe that is achievable for the organization.

As for customizing the testing methodology, the phases listed above will apply regardless of the organization; however, the procedures may vary from customer to customer depending on their environment, the tool used to deploy the patch, the availability of a lab to conduct testing and the resources that are available to spend the time necessary on preparing the patch for deployment.

For more information on patch testing and deployment, visit our Patch Management Project Guide.




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts