Considerations for Patch Management – an RFP Extensive RFP Extensive RFP Pain in the Butt Pain in the Butt 10 Minutes to tell you about it 10 Minutes to tell you about it If you have to do this process – If you have to do this process – RFP in a box – can save you some time RFP in a box – can save you some time Copyright John DeGolyer This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author.
What are you After? Microsoft Microsoft Enterprise, A.D., small departments Enterprise, A.D., small departments Multi- O.S. Multi- O.S. Applications Applications Managed service Managed service Different tools – different situations Different tools – different situations
Big Picture – Step back Why is it failing? Why is it failing? Security – Band Aids on Broken Tech Security – Band Aids on Broken Tech OS not built for these times OS not built for these times Built to share information – “groupware” Built to share information – “groupware” Hippies in Redmond Hippies in Redmond M.S. late to IP Ungerman Bass M.S. late to IP Ungerman Bass
Security is changing - Again Firewalls – port 80 attacks Firewalls – port 80 attacks NATS – “Brittle” accountability NATS – “Brittle” accountability VPN / Encryption – encrypts the attack VPN / Encryption – encrypts the attack Host Firewalls – render scanning useless Host Firewalls – render scanning useless Host IPS – Can’t find systems Host IPS – Can’t find systems New attacks – traditional security methods are failing New attacks – traditional security methods are failing
Our criteria? Yet another agent – Really “smart” agent Yet another agent – Really “smart” agent –Talks over NAT –ET calls home –Reports information –Secure communications –Reports vulnerabilities –Safe configurations –Comprehensive Enterprise view
The Best quality: Patching is an Art – not a science Patching is an Art – not a science 1% - 3% failure rate 1% - 3% failure rate 1% sounds low until the 1% is your Dean 1% sounds low until the 1% is your Dean Clones ? Not really – Dell builds Clones ? Not really – Dell builds Software 5% of project cost Software 5% of project cost High Quality Saves time High Quality Saves time Scaling – SQL licensing – gotcha Scaling – SQL licensing – gotcha Per Server – Expensive over enterprise Per Server – Expensive over enterprise
What did we look at? What do we use? Patchlink Patchlink Bigfix – eEye remediation manager Bigfix – eEye remediation manager St. Bernard St. Bernard Everdream Everdream Ecora Ecora Citidel Citidel Shavlik Shavlik Alteris Alteris