<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130099&AdID=209259&TargetID=2556&Segments=91,115,350,2549,2690,2943,3108,3448,8877,9991,100 60,13943,13985,14402,14497,14750&Targets=39,315,302,2164,2556,2625,2878,6529,10068,10537,10640&Values=34,46,51,63,77,87,91,102,140,203,222,227,279, 382,442,657,940,1311,1716,1767,1785,1925,1970,2299,2310,2327,2352,2678,2767,2862,2878,2942,3890,3904,4080,6236,6293,6325,6352,6389,6391,6392,6393,6 422,6440,6541,6567,6580&RawValues=&Redirect=http://www.apc.com/promo/get.cfm?keycode=e896w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/ee_LEAD_a.gif" WIDTH=728 HEIGHT=90 BORDER=0></A>
home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek 

Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers

Regulatory Resource   Threat Intelligence      Resilient IT      Boardroom Strategies      
Threat Intelligence / Strategies

Smart Vulnerability Management

By Jodi Mardesich

When the worm Blaster hit the Internet last year, many companies were devastated, experiencing downtime and loss of productivity. The worm had been designed to take advantage of a security hole in Microsoft Windows, and where it found that hole, it slinked right through, triggering a denial of service attack.

Not all companies using Microsoft Windows were impacted, however. Those organizations whose CIOs had updated their operating systems in a timely fashion avoided vulnerability to Blaster. The episode demonstrates the business-critical necessity of maintaining a frequent assessment of vulnerabilities and proactively shoring up system weaknesses where discovered.

Though Blaster is becoming a distant memory for many CIOs, malicious hackers continue to take advantage of system vulnerabilities, which are being discovered at the rate of about seven per day, security experts say. The attacks can be costly, too. Last June, for example, hackers exploited a flaw in Microsoft's Internet Information Server and redirected visitors from many commerce and banking sites to a Russian Web site, where sensitive and private customer data was gathered.

The pressure to keep up with software updates has increased. In the past six months, the length of time taken to release code that exploits known system flaws dropped to less than a week. One worm, called Witty, surfaced just two days after the vulnerability it exploited was made public. The likelihood of damage becomes greater when holes are found in widely deployed operating systems and applications. A smart approach to vulnerability management is essential to thwarting potential attacks and maintaining business continuity.

  • Assess Weaknesses. Vulnerability assessment is a process whereby IT professionals make an inventory of their software and hardware assets, track patches and software updates, and manage the deployment of patches and fixes that can prevent potentially devastating attacks. It is not enough to identify vulnerabilities -- smart CIOs should define a process aimed at discovering, prioritizing and managing fixes across a large organization.

  • Make an Inventory. Identify the computers, operating systems, applications, and the versions of all these different components of the network. Find out which have been patched or updated, and how recently. Such an inventory helps to record the status of all aspects of the infrastructure, essentially setting a barometer, before deploying updates.

  • Assess Systems. Determine what needs to be done to protect the network. This process includes identifying security standards and creating policies for how security and standards should be enforced. It also includes periodic scans of the system, checking for viruses and monitoring event logs for intrusion attempts.

  • Keep Current. Knowledge is everything. Scan Web sites and news sources, and sign up for e-mail notification from vendors to be educated on new threats or weaknesses that could be exploited.

  • Educate Staff. Make sure personnel are educated about the company's policies on vulnerability assessment and patch deployment, and that there are sufficient personnel in place to implement strategies. 

Patch Management
 
No vulnerability assessment strategy is complete without an element of patch management. This task requires IT professionals to be informed of the patches that are available, determine which are important to the company to fix, prioritize rolling out the fixes that are necessary and prudent, and do so with the minimum disruption to the day-to-day business. Both applications and operating systems vendors release code to patch security holes in their programs when weaknesses are identified.

The management of patch deployment has become more than an afterthought; it is an essential business practice. More CIOs are choosing to install applications that automate the deployment of patches. Vendors offering such software also track patches and fixes, lessening the burden on corporate IT to do all the research. Whether automation is involved or not, CIOs must make patch management processes a regular part of their vulnerability management strategies by taking the following steps:

  • Do a periodic audit. Find out which updates have been installed, and which haven't. Check the results for completeness.

  • Perform an ongoing patch update. Performing an audit isn't enough; new vulnerabilities are discovered often, as are patches to address those vulnerabilities. Identify an appropriate interval for performing audits, and set deadlines for performing the periodic audits.

  • Set priorities. Determine which fixes are necessary and prudent, keeping business processes top of mind.

Without an effective patch management strategy, corporations can suffer computer downtime, interrupting critical business systems-costing the company, both in dollars and credibility. Strategic patch management strategies help the CIO maintain operational efficiency, overcome security vulnerabilities, and maintain the stability of the corporate environment.

These costly assaults on corporate networks can be avoided with a proactive strategy that combines the assessment of system vulnerabilities and the management of software patch deployment. According to US-CERT, which publishes a database of vulnerabilities, understanding and preparing for potential security problems enables businesses to maintain secure computing environments.

Jodi Mardesich writes about business and is a former staff writer for Fortune.

IT Strategy Center is a daily editorial resource offering innovative insights and strategies for building an integrated, secure and resilient IT infrastructure.

Articles by Topic
Spam and Viruses
Preparedness
Strategies
Related Content
Fast Fact

"System vulnerabilities are being discovered at the rate of about seven per day."


Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR

RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.





Internet Evolution









<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=132180&AdID=212017&TargetID=347&Segments=92,118,335,351,3108,3448,8879,10297,13986,14405,14 496&Targets=40,347,2625,2878,6527,10071,10470&Values=34,46,51,63,77,87,90,102,140,205,222,227,279,382,442,657,940,1431,1716,1767,1785,1925,1945,197 0,2256,2299,2310,2313,2327,2352,2678,2862,2878,3712,3714,3890,3904,4079,6236,6293,6325,6352,6389,6393,6422,6440,6489,6541,6567&RawValues=&Redirect= http://www.informationagenda.techweb.com/?cid=webtile_ms_bi" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/gml/IBM/Leveraging_infoagenda/tile.gif" WIDTH=125 HEIGHT=125 BORDER=0></A>

What's Hot at NWC
Editor's Picks
Network Computing Reports
 


Advertisement
<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130106&AdID=209266&TargetID=294&Segments=94,117,334,353,2567,2692,3108,3448,4080,10296,1398 8,14467,14495&Targets=322,294,298,2625,2878,3348,10067,10535,10641&Values=34,46,51,63,77,87,90,102,140,206,222,227,279,382,442,657,940,1431,1716,17 67,1785,1925,1945,1970,2256,2299,2310,2313,2327,2352,2678,2862,2878,3712,3714,3890,3904,4079,6236,6293,6325,6352,6389,6393,6422,6440,6489,6541,6567 &RawValues=&Redirect=http://www.apc.com/promo/get.cfm?keycode=e897w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/ee_SKY_c.gif" WIDTH=160 HEIGHT=600 BORDER=0></A>


Microsite of the Week

< Advertisement >

Powerful Information at Your Fingertips

 










<A HREF="http://as.cmpnet.com/event.ng/Type=click&FlightID=130079&AdID=209235&TargetID=42&Segments=93,116,352,2689,3108,3448,8547,9985,13942,13987,144 93&Targets=42,321,2625,2878,10069,10556&Values=34,46,51,63,77,87,91,102,140,204,222,227,279,442,657,1311,1716,1767,1785,1798,1925,1970,2299,2310,23 13,2327,2352,2678,2767,2862,2878,2942,3712,3714,3890,3904,4079,6236,6293,6325,6356,6359,6389,6391,6392,6393,6422,6440,6541,6567,6580,6643&RawValues =&Redirect=http://www.apc.com/promo/get.cfm?keycode=e901w" target="_top"><IMG SRC="http://i.cmpnet.com/ads/graphics/as5/kls/apc/isx_LEAD_a.gif" WIDTH=728 HEIGHT=90 BORDER=0></A>

InformationWeek Business Technology 

Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business 

ExpoSoftware ConferenceCSI - Computer Security Institute
Black 

HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight 

Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower 

Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights