There's growing concern on the timeliness & thoroughness of patching. I need to
broadcast out an email to the organization's hundreds of IT staff (infra & apps teams)
to emphasize this in a firm (but non-offensive) manner from governance perspective.
Appreciate if anyone can review it's wordings & add on any useful points:
======================================================================
IT teams,
This broadcast is to emphasize the importance of performing timely patch assessment
& obtain downtime where needed to apply patches. The patches may be security or
non-security (ie for functional fixes) related and meant for appliances/devices (eg: for
network/firewall devices) Operating Systems for servers, workstations and hosts,
applications and firmwares/microCodes.
You are urged to :
1.review regularly the availability of patches for the respective products under your
care (via the principal's web page and assess if the released patch(es) are applicable
2. assess if the patch is applicable to the products under your support within 3
working days
3.do test out the patches and seek for approved downtime early so that you have
sufficient time to test out the patches as thoroughly as possible to minimize the
risk of patches causing service disruptions
4.maintain a patch register and update it asap after patching has been done
5. As a good practice, apply patches to development, SIT/UAT before rolling
out to production environment
Failing to apply patches timely will result in extended exposure to vulnerabilities
and product defects/issues
For your attention and compliance,
IT Security Governance
IT teams including apps teams, Network, Servers, Ops, IT Security : Audit finds the
procedure inadequate to meet local regulatory requirement and I'm broadcasting it
as a way to supplement this.
Calling individual meetings after the broadcast is what I have in mind.
There's quite a few lapses & audit issued faults (& certainly hold IT Compliance
partially accountable for these lapses).
Thanks for suggesting strong words like "shall" etc