Home > Ask the Security Channel Experts > Security Management Questions & Answers > Should hotfix testing be performed by the QA department or by support?
Ask The Security Channel Expert: Questions & Answers
EMAIL THIS

Should hotfix testing be performed by the QA department or by support?

Ira Winkler EXPERT RESPONSE FROM: Ira Winkler

Pose a Question
Other Security Channel Categories
Meet all Security Channel Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 05 March 2007
In your opinion should patch testing/hot fix testing be performed by QA department or the support organization?

>

The answer depends on the organization and the applications involved. Many organizations don't have the luxury of a formal QA department. The administrators are the only people who have the resources to fully test the system.

Generally for patch testing, I also recommend using different policies for end-user systems and servers. You may also want to develop different policies for different servers. Generally, I recommend automatically pushing out patches to end-user systems. There is always the risk of some issues with the patch, however the clear of majority of the time, you are greatly decreasing the risks on the most abundant systems out there.

When servers are concerned, QA departments can often perform a more thorough testing of patches before they go live because they have standard procedures for making sure the current patch doesn't break anything, and for regression testing as well. Support departments usually have numerous responsibilities and are frequently overworked. I generally doubt that most support departments have formal testing procedures, but if they do, they have to interrupt a routine workflow to test a new patch. This is why I am very much in favor of scheduled patch releases by vendors, as it helps overworked support departments plan their time.

So all things being equal, if there are QA departments in place, they should be responsible for testing patches.

Don't forget to visit our Patch Management Project Guide for a collection of helpful resources.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security Management
Hardening Linux as part of your client's network security policy
Implementing wireless LAN security policies for mobile users
Complying with the Federal Information Security Management Act (FISMA)
Automated patch management for SMB customers
Understanding ISO 27001 and ISO 17799
Maintaining HIPAA compliance
How do I create a repeatable patch testing methodology?
Creating security policies for an enterprise customer
Implementing third-party patches on customer systems
Patch management system post-deployment considerations for VARs and consultants

Vulnerability and patch management
Mitigating zero-day vulnerabilities in customers' environments
Despite customer interest, channel struggles with threat management
Portcullis Systems adds HP security products to Microsoft customers
Agilex partners with HBGary to offer security forensic, assessment services
Snort vs. Microsoft Security Bulletin MS08-068
Top security tips for solutions providers
Top five security service provider tips of 2007
The true cost of offering patch management services
Microsoft WSUS deployment guide
Antivirus software patch management

Security Patch Testing
How do I create a repeatable patch testing methodology?
Testing patches virtually saves money and space
Patch testing on the cheap
Implementing third-party patches on customer systems

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts