On 18/08/2011 14:22, Levy, Alan wrote:
How often do you patch your linux servers.
As often as necessary :)
I have been patching once every 3-4 months (over 100 servers - sles 9 thru 11) and have been told that I had to start patching much more frequently. I'd like to find out what other people are doing.
I wouldn't buy any arbitrary frequency for patching (unless I'm wearing a Windows hat and it's Patch Tuesday). A better question to answer, for sysadmins, security, and auditors, is "what un-applied patches exist for our systems?" You get this by combining discovery, triage, and patching itself. If you don't do discovery for 3 months, how will you know about the next "critical" update? Triage can be outsourced to an degree, if you take the vendor's metadata and the CVSS rating, or something similar. Policy then is an agreement of if/when to patch. Network attack from unauthenticated user leading to root-level access? Maybe patch sooner. Fix that corrects a memory leak in bash? Maybe patch later. Update to the latest version of the printer database? Maybe patch never. If you can state with certainly which patches remain unapplied, and point to the policy that covers the patching priority for your organization, then you're in good shape. Cheers, Phil ---------------------------------------------------------------------- For LINUX-390 subscribe / signoff / archive access instructions, send email to [email protected] with the message: INFO LINUX-390 or visit http://www.marist.edu/htbin/wlvindex?LINUX-390 ---------------------------------------------------------------------- For more information on Linux on System z, visit http://wiki.linuxvm.org/
