Solved

Best Practices for Critical and Security Patches in Banking Environment

Posted on 2014-03-23
5
381 Views
Last Modified: 2014-04-11
We have a bank client with whom we provide IT and Managed Services.  In the new contract, they are asking us to provide, among other things,  the following:

       Quarterly analysis and delivery of customized patch bundle, monitor patches as released.  Critical Security Patches shall be addressed quarterly or on an as-need basis. Critical Patch Updates will be provided within 3 days after OEM release.  (FIRST ABC BANK needs to be notified on all critical and high risk alerts). All patches require testing prior to releasing into the FIRST ABC Bank environment.

QUESTION:  What is the best practical way to apply critical updates and security patches that meets these requirements?

Microsoft recommends updates to be applied in a test environment first to ensure compatibility.  This is impossible.  There is no way the bank can maintain a fully functional "test" environment with all their corporate applications installed and current, to "test" Microsoft's constant releases, critical updates, security updates, fixes to updates, fixes to fixes, etc.

We are being asked to sign the contract with such wording in the contract---test before deployment.  

Please provide recommendations!

Thanks in advance!

Regards,
SFJCPU
0
Comment
Question by:sfjcpu
5 Comments
 
LVL 24

Expert Comment

by:Mohammed Khawaja
Comment Utility
As part of the agreement and best practices, ask the bank to setup a test environment.
0
 
LVL 25

Expert Comment

by:Tony Giangreco
Comment Utility
As mentioned above, setup a test environment with the same apps used in the bank.  Document the environment and run tests after applying the security updates. Maintain a log of results after each update is applied for your protection and the ability to backup the work you have performed.
0
 
LVL 25

Expert Comment

by:madunix
Comment Utility
When implementing updates, I prefer to plan ahead, test on a non-critical server, create a change plan B, also be sure to read the release notes, there may be special instructions related some patches.
0
 

Author Comment

by:sfjcpu
Comment Utility
Thanks for the above comments.  

With a complex network such as a banking environment, with many servers and applications, is it practical to set up an test environment where all Microsoft security and critical updates can be applied before deploying in the "real" network?  

Compliance requires them to be installed soon after release but there are unforseen risks when they are installed.  We all have a limited amount of time to research every patch!

I like "madunix's" comment on planning ahead, reading the release notes but it still comes down to deciding on:
1.  being compliant for the auditors,
2.  being at risk for having unpatched systems,
3.  taking the risk of installing updates in a live environment.  

This surely is a dilemma for many IT professionals!   How are others balancing the problem?
0
 
LVL 24

Accepted Solution

by:
Mohammed Khawaja earned 500 total points
Comment Utility
We are not a bank but what we do is that we create snapshots for virtualized environments prior to patching as well as system state backup and for non-virtualized, we ensure to take a system state backup of the servers.  In case of failure, we could revert the snapshot or system state.
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

Suggested Solutions

Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
Read about achieving the basic levels of HRIS security in the workplace.
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now