In today’s episode I talk about patching various types of systems and my recommendations for each.
BIOS/FirmwareUpdate at deployment then as neededDriversUpdate at deployment then as needed OSUpdate monthly Delay one month from release date unless critical ApplicationsEnable auto-update if available Update monthly if reasonable, otherwise as neededLevel of effort CostBIOS/FirmwareUpdate at deployment then as neededDriversUpdate at deployment then as neededOSUpdate monthly Delay one month from release date unless critical ApplicationsDeploy stable version and update annually or as neededFirmwareDeploy stable version and update annually or as neededFirmwareDeploy stable version and update annually or as neededDriversDeploy stable version and update as neededSmartphonesUpdate major version as stable Enable auto-update for minor version if historically stable Apps should auto-update, delayed if necessary for testing TabletsUpdate major version as stable Enable auto-update for minor version if historically stable Apps should auto-update, delayed if necessary for testing IOTTry to deploy only if reputable manufacturer Enable auto-updatesIntrusion PreventionDeploy stable version and update annually or as neededAccess ControlDeploy stable version and update annually or as neededFire AlarmDeploy stable version and update annually or as neededKeeping systems updated is typically around 25% of your time as a SysAdminDepending on the system much of this work will need to be completed after hoursChoosing how often a system is updated is an important balance between required up time, stability and security