In my virtual CISO consulting engagements and vulnerability and penetration testing, the process of patch management ALWAYS comes up for discussion. Given the threats, the vulnerabilities, and the risks – everything that’s at stake – I cannot think of any single aspect of a well-functioning information security program that’s more important than patch management. It’s one of a few things in security that you CAN control!
The absolute last thing you want facilitating an incident or breach is a software patch that could (should) have been applied. Here are some articles that I have written about the subject over the years that may help you with your efforts:
“A business associate referred our company to Principle Logic when we were seeking a resource to perform vulnerability /penetration testing for our external and internal networks. We found Kevin Beaver to be professional, well informed, and easy to work with. His testing did not disrupt our networks, and his progress updates were timely.
His final report was very thorough and included security recommendations for our network environment. The executive leadership was so impressed with Kevin’s security expertise, they have extended their agreement to continue to perform periodic testing. We highly recommend Kevin Beaver and Principle Logic as a resource for network security testing.”