1) As a rough figure how often do Apach release security patches for Tomcat? I.e. per month, per week, how many?
2) And what tools can admins use to ensure that their apache is kept up to date? Do apache provide any free ones?
3) What would auditors look for when reviewing pacth management procedures for non MS software? For example if you did a scan and it said "apache out of date", they may apply a patch and then rescan and its gone, only for next week 5 more patches to come out and then its insecure again, and the process isnt managed.
4) So what demonstrates good patch management, i.e. what visually shows the auditor that this problem wont happen again?