Test/dev servers patched on month #1. Next month, patched roll to prod if no issue.
We will do "emergency patch" for high profile fixes with known exploits on occasion. -sc > -----Original Message----- > From: Ben Scott [mailto:[email protected]] > Sent: Tuesday, September 29, 2009 5:20 PM > To: NT System Admin Issues > Subject: Re: WSUS question > > On Tue, Sep 29, 2009 at 1:08 PM, Sam Cayze <[email protected]> > wrote: > > Use GPO's to control it. I always use "Auto download and notify for > > install." for servers. > > +1 / "Me too!" / etc. > > Workstations get patches approved practically immediately and get > install forced. > > Servers, I watch for any known issues or active exploitation, and > deploy when it seems like a good idea, typically a week or so after > release. Sooner if it's a "OMG we're all gonna die" security hole. > Later if the web is buzzing about problems with an update. > > -- Ben > > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ > ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~ ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
