Patch Management

Securing IT starts by managing IT

Challenges

The window of exposure (between vulnerabilities discovery and exploit) has dramatically reduced. The biggest challenge for companies is now to plan and prioritise time-consuming remediation process before first attacks occur.

Increasing concern over governance and regulations (HIPAA, Sarbanes-Oxley, for example) has pushed companies to achieve better control and monitoring over their computer resources.

- Continuously monitor patch releases from multiple vendors
- Ensure patch deployment success on distributed systems
- Reduce costs and risks of emergency patching
- Mesure effectiveness of patch deployment on the global security

Patch Management

Criston Solutions

With Precision Patch Management, enterprises can quickly identify missing patches and automatically deliver critical patches and fixes to thousands of end-points. Reducing attacks threat by implementing a proper patch management process can be rapidly effective, as 90% of attacks will exploit security holes for which patches have already been issued.

Missing Patch Inventory

Desktop Management

This inventory generated by the Precision agent provides the list of all missing patches sorted by severity for a single device or consolidated for a group of devices.

- Up-to-date information on required patches
- Intelligence to prioritise, plan and target deployment.

Patching Process

According to IT department needs, different patching methods are available with :
- Baseline Patching: creates a list of baseline patches to be applied to all devices of a group
- Emergency Patching: deploys a specific patch to a group of machines without interrupting the normal patch cycle
- Automatic Patching: specifies filters so all patches that match will be downloaded and ready to be installed.

Patch Deployment

Using the agent-based architecture of Criston Precision, Patch Management benefits from Criston’s expertise in application deployment within complex distributed networks.

Safe Reboot

Precision Patch Management offers the most flexible reboot options available on the market today. Administrators can choose to reboot systems immediately after patch installation or at a specified date or time. The number and flexibility of these reboot options provides a ’Safe Reboot’ experience for both the administrators and the end users.

Multiple Vendor Support

Precision Patch Management relies on the Shavlik pre-tested patch knowledge base which not only supports Microsoft products but also widely distributed applications
- Improved Patch Fingerprint Accuracy with crossed methods of registry and file detection and versioning
- Pre-tested patched to reduce the amount of development and testing required prior to patch deployment.