If someone told me to patch more frequently - I would make them explain exactly how often and why. For convenience sake, patching every x weeks or months might be nice .. but there should be policies in place that distinguish between security fixes and other types, and give rules/guidelines for how soon such patches should be applied. If these policies don't exist - they should be developed - so I would be working to define that.
There are so many approaches to patching.. 'if it ain't broke, don't fix it' - 'stay a release behind current' - 'apply security fixes immediately' .. that being told 'patch more frequently' doesn't really give you much to go on. What is your strategy when it comes to software maintenance? What are the policies that must be adhered to? What are the maintenance windows that allow you to patch servers? Those seem like better indicators then 'frequency'. Scott Rohling ---------------------------------------------------------------------- For LINUX-390 subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO LINUX-390 or visit http://www.marist.edu/htbin/wlvindex?LINUX-390 ---------------------------------------------------------------------- For more information on Linux on System z, visit http://wiki.linuxvm.org/
