Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Its Time to Standardize Vulnerability Day

    Written by

    Larry Seltzer
    Published July 18, 2005
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Ive seen it coming for a while now. The second Tuesday of the month may be Microsoft patch day, but its evolved into Industry Patch Day.

      This is one of those instances, and they happen more often than youd think, where Microsoft sets the tone for the rest of industry. They didnt invent the security advisory, and heaven knows they wish they didnt have to be so expert in it, but they listened to their customers and they have the process down.

      And now other companies are listening. Not only have they tried to emulate Microsoft, but they are trying to hide behind Microsofts skirts on the second Tuesday of the month. Its a poor substitute for doing things openly and correctly. Part of the correct way is how Microsoft gives notice—three business days before they release their alerts and patches—of how many patches there will be, which products will be affected, the maximum severity of the alerts, and whether systems will need to be rebooted.

      Its all about helping IT plan. Some have criticized Microsoft for holding off patches until the regularly scheduled times, but unless an exploit is imminent, releasing serious, surprise patches is not helpful to an orderly IT department. When a real emergency comes along, the software vendor and customer need to cast schedules aside and expedite matters, but these events are comparatively rare.

      My initial thought about Oracles recent announcements was that they too were tagging along with Microsoft, but one look at Oracles quarterly Critical Patch Update schedule shows that more often than not it will not coincide with Microsofts release dates. Oracle releases on the Tuesday closest to the 15th of January, April, July and October. Microsoft releases on the second Tuesday of the month. This month they coincided, but that was a rarity.

      But would IT be better off if Microsoft and Oracle did release updates at the same time? It would depend on the specifics of the updates, details that are not available until close to the release date. When we get down to that point, for all we know everyone else will have updates too. That would be a really bad month, not unlike this one.

      But while bad months will come every now and then, it is better to plan for the average case. And in the average month, the amount of work involved is not onerous, especially with advance warning. For those who think this months heavy load is a reason not to plan for a common date, bear in mind that its still possible, with no coordination and advance warning, for multiple vendors, including Microsoft, to release updates simultaneously. Wouldnt you rather have advance notice?

      I suppose its not quite so critical that everyone release on the same day. Its the predictability that really matters. Im concerned that if all the major vendors decided to standardize on update release schedules of their own, security personnel would have too many scheduled events to deal with. Probably every individual department, given the software it runs and the availability of its personnel, will have a different attitude, and I would be anxious to hear yours.

      But the information we have from the last couple of years of Microsofts update practices and those of other vendors tells me that its better to have order in the process.

      Next page: Crowded patch days in 2005.

      Crowded Patch Days in

      2005″>

      Below are Microsoft patch days in 2005 and links to information about non-Microsoft patches that were released on the same day or one day off.

      • Jan. 11
      • Apple Fixes iTunes Security Flaw
      • Feb. 8
      • SuSE Fixes Bugs, Defends New Update Policy
      • Symantec Patches High-Risk Vulnerability
      • March 8
      • Nothing
      • April 12
      • Cisco Patches IOS Security Flaws
      • Oracle Patches Database Vulnerabilities
      • May 10
      • Apple Patches iTunes MPEG Decoding Flaw
      • New Firefox, Mozilla Versions Fix Open Browser Holes
      • June 14
      • Sun Squashes Critical Java Bugs
      • Adobe Plugs Holes in Reader, Acrobat
      • Security Patch Watch: Adobe, Macromedia, Symantec
      • July 12
      • Major Oracle Patch Covers Enterprise Products, Database Server
      • Mozilla Updates Firefox to Fix Security Gaps
      • Apple Patches OS X Flaws
      • Cisco CallManager Multiple Remote Vulnerabilities

      Security Center Editor Larry Seltzer has worked in and written about the computer industry since 1983.

      Check out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      More from Larry Seltzer

      Larry Seltzer
      Larry Seltzer
      Larry Seltzer has been writing software for and English about computers ever since—,much to his own amazement— He was one of the authors of NPL and NPL-R, fourth-generation languages for microcomputers by the now-defunct DeskTop Software Corporation. (Larry is sad to find absolutely no hits on any of these +products on Google.) His work at Desktop Software included programming the UCSD p-System, a virtual machine-based operating system with portable binaries that pre-dated Java by more than 10 years.For several years, he wrote corporate software for Mathematica Policy Research (they're still in business!) and Chase Econometrics (not so lucky) before being forcibly thrown into the consulting market. He bummed around the Philadelphia consulting and contract-programming scenes for a year or two before taking a job at NSTL (National Software Testing Labs) developing product tests and managing contract testing for the computer industry, governments and publication.In 1991 Larry moved to Massachusetts to become Technical Director of PC Week Labs (now eWeek Labs). He moved within Ziff Davis to New York in 1994 to run testing at Windows Sources. In 1995, he became Technical Director for Internet product testing at PC Magazine and stayed there till 1998.Since then, he has been writing for numerous other publications, including Fortune Small Business, Windows 2000 Magazine (now Windows and .NET Magazine), ZDNet and Sam Whitmore's Media Survey.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×