How to Compare Patch Management Software

Patch management software helps organizations acquire, test and install code to fix known vulnerabilities in operating systems and applications. It also helps them assess exposure and prioritize patches (given your specific environment), identify missing patches that need to be remediated and produce real-time reports for compliance and other auditing needs.

By Mary Brandel

Mon, November 09, 2009CSO Patch management software helps organizations acquire, test and install code to fix known vulnerabilities in operating systems and applications. It also helps them assess exposure and prioritize patches (given your specific environment), identify missing patches that need to be remediated and produce real-time reports for compliance and other auditing needs.

Since its emergence early this decade, patch management has become "operationalized," says Ronni Colville, an analyst at Gartner. For instance, the function is being subsumed into PC configuration management vendors' suites, such as Symantec (Altiris) and Avocent (LanDesk). However, she says, in most cases, these systems don't offer the richness of capability provided by point solutions.

Also see Patch Management Systems: Evaluation Criteria and Capabilities

Three main players remain in the point solution market: BigFix, Lumension and Shavlik. Still, Colville says, "no vendor can make a full business on just patch management, so they've brought in other functions." For instance, BigFix has broadened its security focus to include more configuration functions (such as inventory and software distribution), she says, while Lumension and Shavlik have begun to include functions such as security configuration, endpoint vulnerability assessment, and data leakage prevention.

Meanwhile, some companies continue to use Microsoft Windows Server Update Services (WSUS) to patch Windows operating systems and applications because it's free, but it's also more manually intensive.

Patch Management Package Selection: Two Prime Considerations

Configuration management versus patch management. A primary decision is whether to turn to a configuration management system for its patch capabilities or to a point product that may or may not also offer configuration capabilities. According to Colville, the reasons organizations choose the latter is they're not ready to commit to a full lifecycle configuration suite, or their current configuration management tools don't provide a best-of-breed patch management capability. The trade-off of having both in your environment, of course, is the need to deal with multiple agents and consoles.

Eric Maiwald, an analyst at Burton Group, suggests first evaluating your configuration management system for its patch management capabilities, since it might be advantageous and less expensive to maintain the same architecture for both functions, especially if it already works well in your environment. However, if you change your mind, the functionality will be more difficult to remove because the single-vendor approach means the software is embedded more deeply into your architecture.

Agent versus agentless. As Shavlik explains, agentless systems are based on push technology and on a centralized design. Server-based software scans the machines in the enterprise and initiates all actions on those machines. With agent-based solutions, client-based software scans the machine and communicates its findings back to the central console.

BigFix

Loading...
Security MarketSpace
Smarter Protection For the Enterprise
Read this IDC paper for background on today's threat ecosystem with an overview of network security threats, the impact of the threats on enterprises, and the operational challenges faced by IT. Learn more »
Reduce Impact of Unplanned Downtime by 85%
Based on new research, IDC offers best practices to help identify vulnerabilities, "weak links" and mitigate external and internal risks. Learn more »
A Hidden Benefit of Desktop Virtualization?
This IDG eZine explores the many user benefits of desktop virtualization. Learn more »
Controlling E-Discovery: What stays in? What goes out?
You want to hold the cards as far as information management, but keeping large in-house teams doesn't make sense. Learn more »
Get Ahead of Your Data in Early Case Assessment
Need tools that provide cost savings today and fit into a long-term e-discovery strategy? Learn more »
The Challenges of Working with Keyword Search
There is a dangerous assumption that keyword search alone can sufficiently manage e-discovery. Learn more »
How In-House Technology Delivers Savings
Learn how companies can gain control of the e-discovery process and reduce costs by bringing software in-house. Learn more »
Cloud Computing Security
Learn how enterprises and service providers can achieve cloud-ready security for a competitive edge. Learn more »
 
SPONSORED LINKS
 

Making Consumer Two-Factor Authentication Simple and Cost-Effective

Mining the Cloud to Ease the Enterprise Compliance Burden

Solve Five Key IT Security Challenges with Cloud-Based Authentication

IDC White Paper: CCM for IT Compliance and Risk Management

White Paper: A Security Blueprint Delivered From within the Network

Maximizing efficiencies with unified communications.

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion.

Cut Costs & Green Your IT Operations with PC Power Management

Webcast: Unleashing the Power of Customer Data

White Paper: Legacy Tools: Not Built for the Helpdesk

Taking a Seat at the Executive Table: The Reality of Virtualization

The Total Economic Impact of Network Security Intrusion Prevention

Generation Remote Infrastructure Management - Changing the Paradigm

Lower IT Costs with Oracle Database 11g Release 2

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

Five CIO challenges addressed by better change management

CA ARCserve r12.5 is More Than Backup! Download Trial Version Today

Secure & simplify your data center w/Juniper Networks.

Gartner ITxpo Panel Webcast: Real-world Early Adoption of Windows 7.

Masters of Virtualization and Cloud Computing - Daily News

Stay informed with custom newsletters from Tech Dispenser

Trend Micro ranked #1 against real-world malware. Read more.

Streamline IT Costs. Boost Performance with WAN Optimization.

Authentication as a Service by Forrester Research

Cloud-Based Authentication for Next-Generation Extranets

Mobile Security: The Essential Ingredient for Today's Enterprise

Learn about the growing threat of insider data theft.

Efficiency goes up. Costs come down.

Verint Systems. Discover the Power of Intelligence in Action"

Upgrading to VMware vSphere with vWire

See how AT&T can help protect your network.

White Paper: 5 Best Practices for Smartphone Support

Global Research: CIOs Weigh In On Virtualization

White Paper: Next Generation Remote Infrastructure Management

Seven Design Requirements for Web 2.0 Threat Protection

Cloud-Based Email Management: Opinion Shifts In Favor

Achieving Business Agility with Application Grid

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Build your 1st app FREE with Force.com

Read about how to add efficiencies with Microsoft Virtualization.

Dark Fiber from Sunesys Save on Unlimited Bandwidth with Fixed Costs.

Forrester Webcast - Managing Desktop Support Costs

Be Prepared for Windows 7. Register for this Webcast Series.

Top Five CIO Challenges

AT&T Synaptic Storage as a Service. Expand on demand

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Read the RSA report: Security for Business Innovation

 
 
RESOURCE CENTER