Novell. ZENworks Patch Management Design, Deployment and Best Practices. Allen McCurdy Sr. Technical Specialist amccurdy@novell.



Similar documents
Patch Management Reference

Patch Management Reference

Patch Management Reference

ZENworks 11 Support Pack 4 Management Zone Settings Reference. May 2016

Patch and Vulnerability Management Program

Lumension Guide to Patch Management Best Practices

How PatchLink Meets the Top 10 Requirements for Enterprise Patch and Vulnerability Management. White Paper Sept. 2006

ALTIRIS Patch Management Solution 6.2 for Windows Help

Lumension Endpoint Management and Security Suite

Audit Management Reference

The Value of Vulnerability Management*

Northwestern University Dell Kace Patch Management

Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0

Service Release Notes 8.2

VMware vcenter Update Manager Administration Guide

HP ProLiant Essentials Vulnerability and Patch Management Pack Planning Guide

Community Chat. MDM Meets Endpoint Mgmt. Justin Strong Sr. Product Marketing Manager

Novell ZENworks 10 Configuration Management SP3

Software Distribution Reference

Vulnerability Scanning and Patch Management

Managed Service Plans

Providing Patch Management With N-central. Version 7.1

Installing and Administering VMware vsphere Update Manager

Patch Management for Red Hat Enterprise Linux. User s Guide

Patch Management. Module VMware Inc. All rights reserved

AHS Flaw Remediation Standard

CA Vulnerability Manager r8.3

Office 365 Windows Intune Administration Guide

Lumension Endpoint Management and Security Suite Patch and Remediation 7.0 Service Pack 1 Migration Guide

Patch Management Policy

Altiris Patch Management Solution for Linux 7.1 SP2 from Symantec User Guide

Staying Secure After Microsoft Windows Server 2003 Reaches End of Life. Trevor Richmond, Sales Engineer Trend Micro

Managed Antivirus Quick Start Guide

McAfee Security Information Event Management (SIEM) Administration Course 101

Managing Software Updates with System Center 2012 R2 Configuration Manager

Lumension Endpoint Management and Security Suite (LEMSS): Patch and Remediation

McAfee Application Control / Change Control Administration Intel Security Education Services Administration Course

UMHLABUYALINGANA MUNICIPALITY PATCH MANAGEMENT POLICY/PROCEDURE

Administration Quick Start

SECURITY PATCH MANAGEMENT INSTALLATION POLICY AND PROCEDURES

Configuration Information

Anatomy of a Breach: A case study in how to protect your organization. Presented By Greg Sparrow

SSL Management Reference

System Center Configuration Manager

Getting Ahead of Malware

Dell KACE K1000 System Management Appliance Version 5.4. Patching and Security Guide

VMware vcenter Update Manager Administration Guide

Printed and bound in the United States of America. First Printing

HP Server Automation Enterprise Edition

Providing Patch Management With N-central. Version 7.2

NYS LOCAL GOVERNMENT VULNERABILITY SCANNING PROJECT September 22, 2011

eguide: Designing a Continuous Response Architecture Executive s Guide to Windows Server 2003 End of Life

Cautela Labs Cloud Agile. Secured. Threat Management Security Solutions at Work

Vistara Lifecycle Management

Step-by-Step Guide to Securing Windows XP Professional with Service Pack 2 in Small and Medium Businesses

Release Notes for Websense Security v7.2

Novell ZENworks Patch Management Powered by PatchLink Corporation

Altiris Patch Management Solution for Windows 7.1 from Symantec Release Notes

10 BenefIts. that only an Integrated platform security solution can BrIng

IBM Security QRadar Vulnerability Manager Version User Guide

PATCH MANAGEMENT. February The Government of the Hong Kong Special Administrative Region

Devising a Server Protection Strategy with Trend Micro

Kaseya White Paper. Endpoint Security. Fighting Cyber Crime with Automated, Centralized Management.

SapphireIMS 4.0 Asset Management Feature Specification

Providing Patch Management with N-central. Version 9.1

Symantec AntiVirus Business Pack Administrator s Guide

CHAPTER 3 : INCIDENT RESPONSE FIVE KEY RECOMMENDATIONS GLOBAL THREAT INTELLIGENCE REPORT 2015 :: COPYRIGHT 2015 NTT INNOVATION INSTITUTE 1 LLC

Devising a Server Protection Strategy with Trend Micro

Network Detective. Network Detective Inspector RapidFire Tools, Inc. All rights reserved Ver 3D

SOLARWINDS ORION. Patch Manager Evaluation Guide for ConfigMgr 2012

Streamlining Patch Testing and Deployment

Information Technology Services

Idera SQL Diagnostic Manager Management Pack Guide for System Center Operations Manager. Install Guide. Idera Inc., Published: April 2013

Antivirus and Malware Prevention Policy and Procedures (Template) Employee Personal Device Use Terms and Conditions (Template)

Patch management with GFI LANguard N.S.S. & Microsoft SUS

Taking a Proactive Approach to Linux Server Patch Management Linux server patching

AVeS Cloud Security powered by SYMANTEC TM

Symantec Patch Management Solution for Windows 7.5 SP1 powered by Altiris User Guide

User Guide. Lumension Endpoint Management and Security Suite Patch and Remediation 8.0

Using Windows Update for Windows XP

Extreme Networks Security Analytics G2 Vulnerability Manager

SUPPLIER SECURITY STANDARD

Patch management with WinReporter and RemoteExec

Mobile File Access for the Enterprise

Information and Communication Technology. Patch Management Policy

McAfee Total Protection Service Installation Guide

HoneyBOT User Guide A Windows based honeypot solution

Introducing ZENworks 11 SP4. Experience Added Value and Improved Capabilities. Article. Article Reprint. Endpoint Management

TECHNICAL VULNERABILITY & PATCH MANAGEMENT

Integrate Websense Web Security Gateway (WSG)

Novell ZENworks Asset Management

How To Deploy Software Updates Using SCCM 2012 R2

Resolving the Top Three Patch Management Challenges

ForeScout CounterACT CONTINUOUS DIAGNOSTICS & MITIGATION (CDM)

Enabling Security Operations with RSA envision. August, 2009

Getting started. Symantec AntiVirus Corporate Edition 8.1 for Workstations and Network Servers

SOFTWARE UPDATER A unique tool to protect your business against known threats

IBM Managed Security Services (Cloud Computing) hosted and Web security - express managed Web security

Verve Security Center

System Planning, Deployment, and Best Practices Guide

Transcription:

Novell ZENworks Patch Management Design, Deployment and Best Practices Steve Broadwell Sr. Solutions Architect sbroadwell@novell.com Allen McCurdy Sr. Technical Specialist amccurdy@novell.com

Agenda General Patch Management Intro The Patching Cook Book The Near Future 2

Introduction

Patch Management Challenges Issues STILL facing today's organizations: Increasing Threats Faster Threats (Reverse Engineering) Number of Exploits and Vulnerabilities are still Growing Patch Tuesday Policy Compliance Regulatory Compliance Patch Testing 4

Patch Decay Machines become unpatched over time: New machines added Machines re-imaged Old software upgraded or removed New software installed or patched Patches are installed Virus attack User error 5

ZENworks Patch Features Extensive pretesting ZENworks single modular agent Advanced signature recognition Multiple Languages Multiple Operating Systems Multiple Vendors Flexible reporting Auditing ZERO Effort Patching 7

The Process

Patch Management Process 1. Pre-Patching Decisions 2. Enable Patch Management 3. Identify and Assess the Vulnerabilities 4. Obtain the Relevant Patches 5. What Needs to be Patched 6. Testing 7. Patch deployment 8. ZERO Effort Patching 9

Pre-Patching Decisions

Limit the Scope Be Vendor Specific One Operating System Starting Point Start with a specific service pack Post Starting Point Patches Patch impact Prioritize patches What Languages do I need to support? Document 11

Enable Patch Management

Turning on Patch Management What is Patch Activation? 60 day evaluation License Verification Disable Patch Management Agent Features Manage by Exception Staged Roll out Limits available Vulnerabilities Administration Roles Audit Management 13

Getting Available Patch Information Patch Subscription Service What? When? How Long? Configuration Questions What Communication Interval should I use? Is a dedicated Patch server required? Status 14

Identify and Assess the Vulnerabilities

The Vulnerabilities Research the Patches Detailed Patch Information Search and Filter DISABLE all unnecessary vulnerabilities Accurate reporting Agent scan time Bandwidth utilization Use Filters to disable in bulk Stop NEW Patches from Specific Vendors What about custom patches? 16

How Do I Stay on Top of New Patches? Dashboard Recently Released Patches ZCC Released On column Automatic Email Notification Patch Management Status Page New ZENworks Reporting Server ( ZR5 ) Vendor Security Mailing lists and Web sites The National Vulnerability Database Third Party Vulnerability Mailing list The US-CERT Cyber Security Alerts 17

Obtain All Relevant Patches

Cache the Patches Only cache REQUIRED Patches Check the Status on the Status Tab Patch is Cached Patch needs to be Cached (downloaded) Patch is in download process Patch is Disabled Patch is a part of a Baseline Patch could not be Cached (error) What is a Remediation bundle? 19

Patch Replication ZENworks Configuration Manager (ZCM) Primary Servers? ZENworks Sync Schedule Replicate patch bundles at a folder level ZCM Satellite Satellite replication schedules 20

What Needs to be Patched?

Which Patches does a Device Need? Discover Applicable Update ( DAU ) bundle Download Analyze Report Scheduled when and how often? Automatically Assigned When was it last run? Manual force the scan? 22

Testing

Test, Test and Test Again Test Environment Initial Patch Activation Configuration settings ZCM System Updates Test Area in the Live Zone Real life machines UAT Test Scenarios Documentation 24

Patch Deployment

Assign Patch Remediations ZENworks Assignment Bundles Assignment Wizard Group/Folder Association Does not enforce a patch Reboots are honored even if patch is not applicable Patch Deployment Status ZENworks Reporting Server (ZR5) Bundle Status Agent Show Progress Local log files 26

ZERO Effort Patching

Patch Polices Automatic Patch ENFORCEMENT Rule Based Mandatory Baselines on Steroids Automatic applicable patch caching Manual / automatic policy rebuild Multiple Associated Polices Enforcement schedule Configurable Reboot / Prompts Automatic Testing Process 28

The Near Future 29

This document could include technical inaccuracies or typographical errors. Changes are periodically made to the information herein. These changes may be incorporated in new editions of this document. Novell, Inc. may make improvements in or changes to the software described in this document at any time. Copyright 2014 Novell, Inc. All rights reserved. All Novell marks referenced in this presentation are trademarks or registered trademarks of Novell, Inc. in the United States. All third-party trademarks are the property of their respective owners.