Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -3 articles for you...
77

Optimizing Patch Management Through Processes and Strategy

"We see people looking for a tool that will solve all their problems, but what you need is a process; it's not just about the tool," says Felicia Nicastro, senior network systems consultant for International Network Services, a consulting firm that . . . . "We see people looking for a tool that will solve all their problems, but what you need is a process; it's not just about the tool," says Felicia Nicastro, senior network systems consultant for International Network Services, a consulting firm that kicked off a patch management service in September. Nicastro says the biggest mistake companies make is leaving out the processes, such as diligent monitoring for new patches coupled with detailed evaluation, testing, deployment and validation that a team or individual manages. "This typically isn't a task for one person. It has to involve the security group, the operations group and the developers," she says. "So what also makes patching tough is a lack of resources." . Effective patching relies on a systematic methodology; discover key tactics for proficient update administration.. Patch Management, Security Processes, System Updates, Network Security, Patch Evaluation. . LinuxSecurity.com Team

Calendar%202 Dec 10, 2003 User Avatar LinuxSecurity.com Team Server Security
74

Cost-Effective IT Solutions Through Smart Security Patch Evaluation

ROI (return on investment) is a key concept in IT spending today. The board is much more likely to spend money on IT, if ROI can be demonstrated in a reasonable period of time. It's a very sensible, sound business idea. Yet, many companies are actually practicing what could be called negative ROI - they choose IT products which cost them more money the longer they have them. In the current business environment, this could be described as corporate stupidity.. . .. ROI (return on investment) is a key concept in IT spending today. The board is much more likely to spend money on IT, if ROI can be demonstrated in a reasonable period of time. It's a very sensible, sound business idea. Yet, many companies are actually practicing what could be called negative ROI - they choose IT products which cost them more money the longer they have them. In the current business environment, this could be described as corporate stupidity. I'm talking about the vexed question of security patches. Using software which requires frequent patching because of security problems, means you're pouring money down the drain. It creates a situation in business akin to anarchy. What's more, it's a situation which is totally unnecessary because there are solutions to the problem. When a security patch alert is issued you have two options. You can stop whatever it is that you are doing, no matter how important or crucial, and you can spend the day (or next several days) applying patches to servers. Or you can decide that what you had intended to do before you knew about the patch, is vital and cannot be postponed. You then hope nothing will happen. Other factors come into play as well. Installing patches is boringly repetitive and an uninspiring chore, which usually requires expensive, skilled technical staff (probably in short supply) to carry it out. Servers often have to be brought down, so the natural tendency is to postpone patching. The thinking may be to wait until the next patch is required and install both of them together. Whenyou postpone patching, as many people do, you are accepting insecurity as a way of life. . Cost-effectiveness is crucial in tech; selecting the right software updates can help avoid avoidable company costs.. Security Management, Cost-Effective IT Solutions, IT Spending. . Anthony Pell

Calendar%202 May 02, 2003 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200