Catch Of The Week: Patch To Keep Software Up To Date

2022-08-27 15:33:05 By : Ms. Josie Wu

By BECKY RUTHERFORD Los Alamos

What is one of the most important things you can do to increase cyber security at home or at work?

…Throw all your computers in the canyon and go back to typewriters

…Surround your computers with malachite to protect them from viruses

…Keep all of your operating systems and software up to date

Hopefully you all guessed that third option! For businesses, the best option is to maintain a “patch management life cycle” to keep everything up to date across your organization.

Why is this so important?

Perhaps you have heard of the Equifax data breach from back in 2017? This high-profile, high-impact data breach was due to an exploit of a vulnerability in an open source component, Apache Struts – CVE-2017-5638. Apache Struts is a commonly used web framework, used by Fortune 100 companies in education, government, financial services, retail, and media. How much did this breach cost Equifax? The breach resulted in a lawsuit, and it’s estimated they paid out about $700 million to cover losses.

What is a CVE and why should you care? CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws. When someone refers to a CVE, they are referring to a security flaw that’s been assigned a CVE ID number. When a security advisory is issued it usually mentions at least one CVE, these help security professionals coordinate efforts to prioritize and mitigate these vulnerabilities.

What are some patch management best practices for businesses?

It may sound like a lot of work, but when you consider how much it can cost your business you’ll find it’s very much worth it Down and dirty, what are the most important things for home users to keep up to date?

When are updates released? Patch Tuesday, when Microsoft and other vendors release updates, usually falls on the second Tuesday of the month. Updates can also be released out of band, especially if the threat is new and severe. Keep an eye out for updates and make sure you or if you are a business, your IT staff, are applying them in a timely fashion!

Keeping your devices and software up to date is one of the easiest ways to secure your home or business networks from cyber threats. Patch, patch, patch your stuff to help stay secure.

Editor’s note: Becky Rutherford works in information technology at Los Alamos National Laboratory.

Copyright © 2012-2022 The Los Alamos Daily Post is the Official Newspaper of Record in Los Alamos County. This Site and all information contained here including, but not limited to news stories, photographs, videos, charts, graphs and graphics is the property of the Los Alamos Daily Post, unless otherwise noted. Permission to reprint in whole or in part is hereby granted, provided that the Los Alamos Daily Post and the author/photographer are properly cited. Opinions expressed by readers, columnists and other contributors do not necessarily reflect the views of the Los Alamos Daily Post. The Los Alamos Daily Post newspaper was founded by Carol A. Clark on  Feb. 7, 2012.