The process of identifying, testing and deploying security patches in order to reduce the window of exposure to known vulnerabilities.
Patch management is the process by which an organization identifies vulnerabilities in its software, obtains the patches released by vendors, tests them and deploys them across its estate. Its purpose is to reduce the window of exposure, that is, the period during which a known flaw remains exploitable for want of being fixed, a window during which attackers often rush in as soon as a vulnerability is made public. Rigorous patch management is one of the most effective hygiene measures and one of the most closely checked by insurers, its absence or slowness being a major aggravating factor. It runs, however, into a practical tension, because deploying a patch without testing it sufficiently can introduce malfunctions, or even cause an outage, while testing it too long prolongs exposure. This tension has a systemic dimension, since a faulty patch or update can itself cause a massive interruption. Finally, patch management protects only against known flaws, and remains by construction powerless against zero-day vulnerabilities, for which no patch yet exists.
A company delays applying a critical patch to its email server while it tests it. During this delay, attackers exploit the known flaw and break into the system, illustrating the cost of a poorly managed exposure window.
patch management, gestion des correctifs, application des correctifs