Applications Life-cycle Management



Similar documents
CA Client Automation: Patch Manager - Supported Patches

Personal Computer Standard. National Infrastructure Group. National Infrastructure Group, ehealth Leads, ehealth Architecture and Design.

BISHOP S UNIVERSITY PERSONAL COMPUTING HARDWARE & SOFTWARE PURCHASING AND SUPPORT POLICY

OIS. Update on Windows 7 at CERN & Remote Desktop Gateway. Operating Systems & Information Services CERN IT-OIS

Enterprise Site Manager (ESM) & Administrator Console Installation / Uninstall

DVD MAKER USB2.0 Installation Manual

Microsoft Windows Server Update Services Questions & Answers About The Product

Windows 7 IMPLEMENTATION PLAN. Version 1.3

Dualog Connection Suite Hardware and Software Requirements

Quickstart Administration

Northwestern University Dell Kace Patch Management

The Importance of Patching Non-Microsoft Applications

Using Windows Update for Windows 95/98

Worry-FreeTM. Business Security Standard and Advanced Editions. System Requirements. Administrator s Guide. Securing Your Journey to the Cloud8

Fusion Release Notes Versions January 2015

Microsoft Software Update Services and Managed Symantec Anti-virus. Michael Satut TSS/Crown IT Support

HP Client Automation Standard Fast Track guide

Next Generation ProSystem fx Suite. Planning and Implementation Overview

Workshare Professional Secure Document Compliance for Microsoft Office 4.5. Workshare Professional Release Notes

Upgrading Client Security and Policy Manager in 4 easy steps

PEAK DVB-T DIGITAL PCI CARD Installation Manual



System requirements for A+

ivos Technical Requirements V For Current Clients as of June 2014

15. juli Norman Enterprise Security NESEC

ESET Endpoint Security 6 ESET Endpoint Antivirus 6 for Windows

System Requirements for Web Applications

Workstation Management

Q A F 0 3. ger A n A m client dell dell client manager 3.0 FAQ

Dell KACE K1000 System Management Appliance Version 5.4. Patching and Security Guide

Automated Patching. Paul Asadoorian IT Security Specialist Brown University

WA2192 Introduction to Big Data and NoSQL. Classroom Setup Guide. Web Age Solutions Inc. Copyright Web Age Solutions Inc. 1

Dell KACE K1000 Management Appliance. Patching and Security Guide. Release 5.3. Revision Date: May 13, 2011

Operating System Installation and Software Distribution for Windows 7

American Red Cross Learning Center. We welcome you to the NEW

Fiery E100 Color Server. Welcome

Request support: ecentral.graphics.kodak.com

To ensure you have the appropriate equipment and settings please review the following: Software and Hardware Recommendations.

AP ENPS ANYWHERE. Hardware and software requirements

BURNET- ACCESS 2013 ACCESS Primary Health Clinic Network GRHANITE SITE INSTALLATION CHECKLIST

Whitepaper. HOBLink JWT v. 3.2 Sets a New Standard in Remote Access Computing The New Version of the Java RDP Client

Table 1. Requirements for Domain Controller. You will need a Microsoft Active Directory domain. Microsoft SQL Server. SQL Server Reporting Services

A Best Practice Approach to Third Party Patching

Determining Your Computer Resources

Desktop Security. Overview and Technology Guidance. Michael Ramsey Network Specialist, NC DPI

Enterprise Server. Application Sentinel for SQL Server Installation and Configuration Guide. Application Sentinel 2.0 and Higher

Experience with Server Self Service Center (S3C)

OIS. SharePoint at CERN. IT GLM 17-May-2010 Alexandre Lossent IT/OIS. CERN - IT Department CH-1211 Genève 23 Switzerland

SCCM 2012 SP1 16 APRIL AVRIL 2013 CEA 10 AVRIL 2012 PAGE 1. Hepix Bologna Joel Surget

ONLINE COURSES: GETTING STARTED GUIDE

The Importance of Patching Non-Microsoft Applications

System Requirements and Platform Support Guide

The Importance of Patching Non-Microsoft Applications

Protecting Your Organisation from Targeted Cyber Intrusion

Table of Contents Release Notes 2013/04/08. Introduction in OS Deployment Manager. in Security Manager Known issues

INSTALLING SAS 9.2 PHASE 3 ON WINDOWS OPERATING SYSTEMS

Oracle Insurance General Agent Hardware and Software Requirements. Version 8.0

SOLARWINDS ORION. Patch Manager Evaluation Guide

System Requirements for Microsoft Dynamics GP 2015

Citrix EdgeSight Installation Guide. Citrix EdgeSight for Endpoints 5.3 Citrix EdgeSight for XenApp 5.3

Microsoft Security Bulletin MS Critical

Remote Deposit Capture Installation Guide

Backup Exec System Recovery Management Solution 2010 FAQ

Needles The Customizable Case Management Software for Law Firms

SOFTDENT Practice Management Software v14.0 System Requirements. Server. Workstation (without digital imaging)

Information Technology Solutions. Managed IT Services

Needles The Customizable Case Management Software for Law Firms

Symantec Mail Security for Microsoft Exchange

Intellex Platform Security Update Process. Microsoft Security Updates. Version 06-10

Core Protection for Virtual Machines 1

Receptionist-Small Business Administrator guide

7 Steps to Windows 7 Migration Best Practices. Anthony Wainman - Presales Technical Consultant Jay Lakhani Sales Director Codework Inc.

Keeping Up To Date with Windows Server Update Services. Bob McCoy, CISSP, MCSE Technical Account Manager Microsoft Corporation

Data Sheets RMS infinity

SecureClient Central Installation Guide. September 2014

Customer Responsibilities

Tracking Anti-Malware Protection 2015

PGP Command Line Version 10.0 Release Notes

Manuals for This Product

Web Supervisor/Agent. System Requirements & Troubleshooting Guide. 989 Old Eagle School Road Wayne, PA (610)

ITNW 2305 Network Administration COURSE SYLLABUS

Taking a Proactive Approach to Patch Management. B e s t P r a c t i c e s G u i d e

ELECTRONIC QUALITY MANAGEMENT SOFTWARE

THOMSON REUTERS EIKON PC REQUIREMENTS THOMSON REUTERS EIKON 4.0

Altiris Patch Management Solution for Windows 7.1 from Symantec Release Notes

Microsoft Security Bulletin MS Important

P3PC ENZ0. Troubleshooting. (installation)

Endpoint Business Products Testing Report. Performed by AV-Test GmbH

System Requirements for TaxWise November 21, 2011

MS SQL Installation Guide

Accessing Windows 7 in the Student Labs

CYCLOPE let s talk productivity

Complete Patch Management

System Requirements Guide

McAfee Policy Auditor Content Update Summary. New Checks

Symantec Backup Exec 12.5 for Windows Servers. Quick Installation Guide

HP OpenView Service Desk

How PatchLink Meets the Top 10 Requirements for Enterprise Patch and Vulnerability Management. White Paper Sept. 2006

HELP DOCUMENTATION E-SSOM INSTALLATION GUIDE

Transcription:

Windows Desktop Applications Life-cycle Management Sebastien Dellabella, Rafal Otto Internet Services Group IT Department

Agenda Components of the Windows application management activity at CERN Application pool Deployment tools Monitoring tools Managing updates and communicating with the users community Case Studies Acrobat Reader : responding to vulnerability disclosures Microsoft Office : follow up of the product evolution Java : how to manage unmanaged? Windows Desktop Applications Life-cycle Management - 2

Overview Snapshot of the environment ~ 6000 managed Windows machines 95% of Windows XP Sp2 5% of Windows Vista ~40 different sets of computers Having different sets of applications Local administrators can manage them using a delegation mechanism Typical managed computers have access to 20 core applications ~100 applications are available on demand In addition: updates, service packs or patches Windows Desktop Applications Life-cycle Management - 3

Application Support Levels Examples Installation Usage Forced Updates Microsoft Office X X X Optional Updates E-mail Notifications Hummingbird Exceed Adobe Flash Player X X X X Sun Java X X X Apple QuickTime X X Windows Desktop Applications Life-cycle Management - 4

Application Support Levels Examples Installation Usage Forced Updates Optional Updates E-mail Notifications Monitoring Microsoft Office X X X X Hummingbird Exceed Adobe Flash Player X X X X X X X Sun Java X X X X Apple QuickTime X X Windows Desktop Applications Life-cycle Management - 5

Processes and Tools Deployment CMF Group Policy Reacting Upgrade Uninstall Block Warn users Monitoring CMF Inventory Antivirus Stats Security and Editors Websites Users feedback Windows Desktop Applications Life-cycle Management - 6

Deployment Tools CMF: Computer Management Framework Application deployment system used at CERN Address requirements of Control community in context t of CNIC More flexible than previously used solution (especially for delegation) Used to deploy all applications at CERN Group Policies Used to deploy all settings and preferences CMF client is deployed using Group Policies Windows Desktop Applications Life-cycle Management - 7

Monitoring Tools Key components of our monitoring activity CMF Inventory Monitoring Websites Statistics Users Feedback Windows Desktop Applications Life-cycle Management - 8

Monitoring Tools Key components of our monitoring activity CMF Inventory Monitoring Websites Statistics Users Feedback Windows Desktop Applications Life-cycle Management - 9

Monitoring Tools Key components of our monitoring activity CMF Inventory Monitoring Websites Statistics Users Feedback Windows Desktop Applications Life-cycle Management - 10

Monitoring Tools Key components of our monitoring activity CMF Inventory Monitoring Websites Statistics Users Feedback Windows Desktop Applications Life-cycle Management - 11

Monitoring Tools Statistics Windows Desktop Applications Life-cycle Management - 12

Monitoring Tools Statistics (2) Windows Desktop Applications Life-cycle Management - 13

Reacting S E V E R I T Y Upgrade smoothly: We group mandatory updates every month Optional updates may be published anytime Progressive deployment Send email alert and/or schedule update: If an exploit is in the wild for a monitored software (i.e. Java) Y Block an installed software: If a vulnerability is widely exploited and no update available Windows Desktop Applications Life-cycle Management - 14

Agenda Components of the Windows application management activity at CERN Application pool Deployment tools Monitoring tools Managing updates and communicating with the users community Case Studies Acrobat Reader : responding to vulnerability disclosures Microsoft Office : follow up of the product evolution Java : how to manage unmanaged? Windows Desktop Applications Life-cycle Management - 15

Case Studies Acrobat Reader: Reacting to vulnerabilities Deployment Supported application preinstalled on each Windows computer by default Monitoring Arbitration to stay with version 7.0.9 and being able to upgrade to version 8.0 if required. Version 7.0.9 was working fine but: 4 critical vulnerabilities since 01-2007 Version 8.0 solved vulnerabilities but: Printing problem with version > 7.0.9 Only first page of the document printed when Postscript driver used Reacting Decided to upgrade to version 8 at the end of 2007 Migrate Postscript drivers to PCL first Windows Desktop Applications Life-cycle Management - 16

Case Studies Microsoft Office (in 2007): Product evolution Deployment at CERN (2007) Office 2003 as default Office suite preinstalled on each new computer Office XP still supported and installed widely at CERN Monitoring Microsoft released Office 2007 (11-2006) Big change in functionality Suitable only for powerful computers (> 1GB of memory) Increasing user demands for the new version Wild installations started to appear Reacting In order to limit number of supported Office suites Office 2007 deployment combined with Office XP phase out Package for Office 2007 has been prepared and optional upgrade announced New training courses were organized After some time (08-2007) Office 2007 became the default Office suite preinstalled on all computers having at least 1 GB of RAM Windows Desktop Applications Life-cycle Management - 17

Case Studies Microsoft Office (in 2008): Product evolution Deployment at CERN (2008) Office 2007 default Office suite on new computers (03-2008) Office 2003 SP2 installed on 80% of computers Monitoring Microsoft releases monthly security patches Microsoft released Office 2003 SP3 and Office 2007 SP1 (09-2007) Reacting Gradual deployment of Service Packs on centrally managed computers Updates proposed to local administrators to schedule them according to their needs Windows Desktop Applications Life-cycle Management - 18

Case Studies Microsoft Office (in 2008): Follow-up evolution Deployment progression of MS Office Windows Desktop Applications Life-cycle Management - 19

Case Studies Sun Java: manage the unmanaged Deployment Three branches of Java are packaged by us and made available for installation (1.4.x, 1.5.x and 1.6.x) Monitoring Computers very often have multiple versions of Java installed We cannot force updates Many critical experiment applications require a particular version of Java Vulnerabilities are disclosed almost every month! Reacting Packages for each new version are created E-mail notifications are sent automatically to owners of vulnerable computers E-mail notifications are sent automatically to local administrators encouraging them to deploy new packages Windows Desktop Applications Life-cycle Management - 20

Case Studies Sun Java: manage the unmanaged Mail sent to Local administrators Windows Desktop Applications Life-cycle Management - 21

Case Studies Sun Java: manage the unmanaged Mail sent to computer s owners Windows Desktop Applications Life-cycle Management - 22

Summary Application lifecycle management Application monitoring activity increased over the years Statistics, i Websites, RSS Feeds, etc. Monitoring is now focused on security rather than application improvement. Deployment is easier Packaging technologies are now mature Our tools allow us to react fast and with modularity Making a package and deploying it CERN wide is possible in 30min! Presentation title - 23

Questions? Presentation title - 24