1
00:00:00,000 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:03,030
we're going to discuss patch management.

3
00:00:03,030 --> 00:00:05,430
So what exactly is patch management?

4
00:00:05,430 --> 00:00:07,650
Well, patch management is the planning, testing,

5
00:00:07,650 --> 00:00:10,290
implementing and auditing of software patches.

6
00:00:10,290 --> 00:00:12,780
Patch management is critical for providing security,

7
00:00:12,780 --> 00:00:14,820
increasing uptime, ensuring compliance,

8
00:00:14,820 --> 00:00:16,860
and improving features in your network, devices,

9
00:00:16,860 --> 00:00:18,630
servers, and clients.

10
00:00:18,630 --> 00:00:21,120
Patch management increases the security of your network

11
00:00:21,120 --> 00:00:23,100
by fixing known vulnerabilities in your network

12
00:00:23,100 --> 00:00:24,960
devices, servers, and clients.

13
00:00:24,960 --> 00:00:26,520
And in terms of servers and clients,

14
00:00:26,520 --> 00:00:27,840
patch management is going to be conducted

15
00:00:27,840 --> 00:00:30,660
by installing software or operating system patches in order

16
00:00:30,660 --> 00:00:33,090
to fix bugs in the system software.

17
00:00:33,090 --> 00:00:35,220
Now, patch management can also increase the uptime

18
00:00:35,220 --> 00:00:37,230
of your systems by ensuring that your devices

19
00:00:37,230 --> 00:00:38,820
and software remain up to date

20
00:00:38,820 --> 00:00:40,650
and don't suffer from resource exhaustion

21
00:00:40,650 --> 00:00:44,040
or crashes due to vulnerabilities inside of their code.

22
00:00:44,040 --> 00:00:45,360
Patch management is also used

23
00:00:45,360 --> 00:00:47,130
to support your compliance efforts.

24
00:00:47,130 --> 00:00:48,900
Now, one of the biggest things that's looked at from

25
00:00:48,900 --> 00:00:50,340
a compliance standpoint is

26
00:00:50,340 --> 00:00:52,590
how well your patch management program is being run,

27
00:00:52,590 --> 00:00:55,230
and how effectively your systems are being protected against

28
00:00:55,230 --> 00:00:57,690
known vulnerabilities like those CVEs

29
00:00:57,690 --> 00:00:59,850
that have patches associated with them.

30
00:00:59,850 --> 00:01:01,470
Patch management is also going to be used

31
00:01:01,470 --> 00:01:02,850
to provide improvements and upgrades

32
00:01:02,850 --> 00:01:04,560
to your existing feature set.

33
00:01:04,560 --> 00:01:07,380
While many patches will only fix existing problems or bugs,

34
00:01:07,380 --> 00:01:09,300
there's also other types of patches out there

35
00:01:09,300 --> 00:01:11,700
that include feature or functionality updates.

36
00:01:11,700 --> 00:01:13,260
By ensuring that you're running the latest version

37
00:01:13,260 --> 00:01:15,930
of the software and that it is fully up to date and patched,

38
00:01:15,930 --> 00:01:17,970
you can ensure that you have the best feature set available

39
00:01:17,970 --> 00:01:20,070
with the highest levels of security.

40
00:01:20,070 --> 00:01:22,230
Now, as you can probably imagine, there are a lot

41
00:01:22,230 --> 00:01:23,370
of different patches out there

42
00:01:23,370 --> 00:01:26,160
because each manufacturer is going to create their own patches

43
00:01:26,160 --> 00:01:28,170
for their applications and software.

44
00:01:28,170 --> 00:01:30,840
Part of our job as cybersecurity professionals is to be able

45
00:01:30,840 --> 00:01:32,700
to keep track of all the various updates

46
00:01:32,700 --> 00:01:35,010
and ensure that all being installed properly throughout

47
00:01:35,010 --> 00:01:37,140
our network to all of our different endpoints

48
00:01:37,140 --> 00:01:40,320
to fully harden our network devices, servers, and clients.

49
00:01:40,320 --> 00:01:41,640
Now, that's a pretty big job,

50
00:01:41,640 --> 00:01:43,770
and patch management is not just concerned with ensuring

51
00:01:43,770 --> 00:01:45,090
that a patch is installed,

52
00:01:45,090 --> 00:01:47,100
but also that it doesn't create new problems

53
00:01:47,100 --> 00:01:49,290
for us once we install that patch.

54
00:01:49,290 --> 00:01:51,750
After all, patches can also have bugs in them,

55
00:01:51,750 --> 00:01:53,940
just like any other piece of software can.

56
00:01:53,940 --> 00:01:56,370
Therefore, to effectively conduct patch management,

57
00:01:56,370 --> 00:01:59,190
you really should follow a basic four step process

58
00:01:59,190 --> 00:02:02,850
of planning, testing, implementing, and auditing.

59
00:02:02,850 --> 00:02:04,590
Now, step one is planning.

60
00:02:04,590 --> 00:02:06,720
Planning consists of creating policies, procedures,

61
00:02:06,720 --> 00:02:09,330
and systems to track the available patches and updates,

62
00:02:09,330 --> 00:02:11,220
and then having a method in place to verify

63
00:02:11,220 --> 00:02:13,140
that they're compatible with your systems.

64
00:02:13,140 --> 00:02:15,360
Planning is also used to determine how you're going to test

65
00:02:15,360 --> 00:02:18,600
and deploy each of those patches before you install them.

66
00:02:18,600 --> 00:02:21,030
A good patch management tool can really tell you whether

67
00:02:21,030 --> 00:02:23,130
or not the patches have been deployed, installed,

68
00:02:23,130 --> 00:02:26,160
and verified functionally on a given server or client.

69
00:02:26,160 --> 00:02:28,410
For example, in a large enterprise network,

70
00:02:28,410 --> 00:02:31,170
you might use the Microsoft Endpoint Configuration Manager,

71
00:02:31,170 --> 00:02:33,030
or you might buy a third party tool

72
00:02:33,030 --> 00:02:35,130
to help you conduct your patch management.

73
00:02:35,130 --> 00:02:36,900
Step two, testing.

74
00:02:36,900 --> 00:02:38,640
Now, while we're conducting patch management,

75
00:02:38,640 --> 00:02:39,750
it's always going to be important

76
00:02:39,750 --> 00:02:42,660
to test the patches we receive from the manufacturer prior

77
00:02:42,660 --> 00:02:45,480
to automating its deployment throughout your entire network.

78
00:02:45,480 --> 00:02:47,580
As I said before, while a patch is designed

79
00:02:47,580 --> 00:02:50,130
to solve one problem, it can often insert new code

80
00:02:50,130 --> 00:02:53,010
that creates new problems for you if you're not careful.

81
00:02:53,010 --> 00:02:54,360
Within your organization,

82
00:02:54,360 --> 00:02:56,310
you should have a small test network lab,

83
00:02:56,310 --> 00:02:59,040
or at the very least, a single workstation that you can use

84
00:02:59,040 --> 00:03:00,240
for testing a new patch

85
00:03:00,240 --> 00:03:03,390
before you deploy it across your entire network environment.

86
00:03:03,390 --> 00:03:04,290
After all,

87
00:03:04,290 --> 00:03:06,480
many of our organizations have unique configurations

88
00:03:06,480 --> 00:03:08,490
within our networks, and that can actually break some

89
00:03:08,490 --> 00:03:11,010
of the security patches when you try to install them.

90
00:03:11,010 --> 00:03:12,810
So, while manufacturers are attempting

91
00:03:12,810 --> 00:03:15,480
to ensure patches are not going to cause harm to our systems,

92
00:03:15,480 --> 00:03:17,100
this simply cannot be guaranteed

93
00:03:17,100 --> 00:03:20,370
because every network has its own individual configurations.

94
00:03:20,370 --> 00:03:22,380
So instead, it's much better to find out

95
00:03:22,380 --> 00:03:24,720
that the patch is causing issues in your lab environment

96
00:03:24,720 --> 00:03:27,480
before you start pushing it out across 10,000 workstations,

97
00:03:27,480 --> 00:03:29,010
and then have all your end users yelling

98
00:03:29,010 --> 00:03:30,810
and screaming at you because their systems are

99
00:03:30,810 --> 00:03:33,090
crashing and they can't get their work done.

100
00:03:33,090 --> 00:03:35,220
Step three is implementation.

101
00:03:35,220 --> 00:03:37,500
Now, after we test the patch, it's going to be time for us

102
00:03:37,500 --> 00:03:39,060
to deploy it to all of our workstations

103
00:03:39,060 --> 00:03:40,860
and servers that need that patch.

104
00:03:40,860 --> 00:03:43,170
You can do this manually by going to each system

105
00:03:43,170 --> 00:03:45,540
and installing it, or you could do it automatically

106
00:03:45,540 --> 00:03:47,550
by deploying the patch to your client's workstations

107
00:03:47,550 --> 00:03:49,140
and servers so that it's installed

108
00:03:49,140 --> 00:03:51,150
and moved into a production environment.

109
00:03:51,150 --> 00:03:53,280
Now, if you have a small network with only a few clients

110
00:03:53,280 --> 00:03:55,440
or servers like your home network, you may choose

111
00:03:55,440 --> 00:03:57,750
to manually install the patch across the network.

112
00:03:57,750 --> 00:03:59,430
But if you're working for a large company

113
00:03:59,430 --> 00:04:01,530
that has a really big network, you're going to want

114
00:04:01,530 --> 00:04:04,260
to use some sort of tool to perform your patch management.

115
00:04:04,260 --> 00:04:06,540
Now again, Microsoft provides a great tool known

116
00:04:06,540 --> 00:04:08,820
as the Microsoft Endpoint Configuration Manager

117
00:04:08,820 --> 00:04:10,260
that you can use for this purpose,

118
00:04:10,260 --> 00:04:12,960
or you can license a third party patch management tool

119
00:04:12,960 --> 00:04:13,950
that has additional features

120
00:04:13,950 --> 00:04:16,140
and functions that you may be interested in.

121
00:04:16,140 --> 00:04:19,260
Now, some organizations do rely on automatic updates using

122
00:04:19,260 --> 00:04:20,820
the Windows update system,

123
00:04:20,820 --> 00:04:23,430
but most large organizations won't do that.

124
00:04:23,430 --> 00:04:25,500
Instead, they want to have complete control over the

125
00:04:25,500 --> 00:04:27,060
installation of patches.

126
00:04:27,060 --> 00:04:30,000
For large organizations, it is really highly recommended

127
00:04:30,000 --> 00:04:31,530
that you essentially manage your updates

128
00:04:31,530 --> 00:04:33,120
through an update server instead

129
00:04:33,120 --> 00:04:35,070
of using the Windows update tool.

130
00:04:35,070 --> 00:04:37,470
By doing this, you're going to be able to test the patch prior

131
00:04:37,470 --> 00:04:40,110
to deploying it inside of your network environment.

132
00:04:40,110 --> 00:04:42,690
To disable Windows update on your systems, you simply need

133
00:04:42,690 --> 00:04:44,610
to disable the Windows update service from running

134
00:04:44,610 --> 00:04:46,140
automatically on the workstation

135
00:04:46,140 --> 00:04:48,000
whenever it's being booted up.

136
00:04:48,000 --> 00:04:50,220
Now, if you have a lot of mobile devices in your network,

137
00:04:50,220 --> 00:04:52,500
you also need to implement patching there too,

138
00:04:52,500 --> 00:04:55,710
and you do this through an MDM or Mobile Device Manager.

139
00:04:55,710 --> 00:04:57,750
Now, even if you don't have a dedicated test network

140
00:04:57,750 --> 00:05:00,300
or lab environment to use during your testing phase here,

141
00:05:00,300 --> 00:05:02,970
you can split up your production network into smaller groups

142
00:05:02,970 --> 00:05:05,430
and use those as a form of test environment.

143
00:05:05,430 --> 00:05:06,270
For example,

144
00:05:06,270 --> 00:05:08,760
in one of the large organizations I led in the past,

145
00:05:08,760 --> 00:05:10,050
we actually used this concept

146
00:05:10,050 --> 00:05:12,900
of patch rings when we're deploying our new patches.

147
00:05:12,900 --> 00:05:15,030
Inside of Patch Ring 1, we only had 10

148
00:05:15,030 --> 00:05:16,830
or 20 end user machines that we needed

149
00:05:16,830 --> 00:05:18,660
to deploy our patches to first.

150
00:05:18,660 --> 00:05:20,160
Then if nothing was broken

151
00:05:20,160 --> 00:05:22,500
and we didn't hear about any issues, we would deploy it out

152
00:05:22,500 --> 00:05:26,010
to Patch Ring 2, which contained 50 or 100 machines.

153
00:05:26,010 --> 00:05:27,420
This included our system administrators

154
00:05:27,420 --> 00:05:29,100
and our service desk workstations too,

155
00:05:29,100 --> 00:05:31,920
so we could see quickly if something was going wrong.

156
00:05:31,920 --> 00:05:34,080
After that, we'd move into Patch Ring 3,

157
00:05:34,080 --> 00:05:36,510
which contained about 1000 to 2000 machines.

158
00:05:36,510 --> 00:05:39,300
And once that was successful, we moved into Patch Ring 4,

159
00:05:39,300 --> 00:05:41,640
which included the rest of the network, which was about 10

160
00:05:41,640 --> 00:05:44,610
to 20,000 machines at the time I was working there.

161
00:05:44,610 --> 00:05:46,590
Now, the benefit of doing these types of deployments

162
00:05:46,590 --> 00:05:48,540
as we move through these various patch rings is

163
00:05:48,540 --> 00:05:51,000
that if there's an issue, we're only affecting a smaller

164
00:05:51,000 --> 00:05:53,287
group of users before we break all 10,000

165
00:05:53,287 --> 00:05:55,110
or 20,000 user computers.

166
00:05:55,110 --> 00:05:57,600
And this saves us a lot of work at the service desk

167
00:05:57,600 --> 00:05:59,520
because we're not going to have to field 10,000 calls.

168
00:05:59,520 --> 00:06:01,740
We'll only have to field 5 or 10 calls.

169
00:06:01,740 --> 00:06:03,510
Now, step four is auditing.

170
00:06:03,510 --> 00:06:04,680
Auditing is important to ensure

171
00:06:04,680 --> 00:06:06,180
that you understand the client status

172
00:06:06,180 --> 00:06:08,340
after you conducted your patch deployment.

173
00:06:08,340 --> 00:06:10,710
During auditing, you're going to be able to scan the network

174
00:06:10,710 --> 00:06:12,900
and determine if the patch was installed properly,

175
00:06:12,900 --> 00:06:15,060
if there's any unexpected failures that may have occurred

176
00:06:15,060 --> 00:06:16,770
because of that installation.

177
00:06:16,770 --> 00:06:18,210
Again, using a tool like

178
00:06:18,210 --> 00:06:20,310
the Microsoft Endpoint Configuration Manager

179
00:06:20,310 --> 00:06:22,200
or a third party patch management tool,

180
00:06:22,200 --> 00:06:23,310
we'll be able to conduct scanning

181
00:06:23,310 --> 00:06:26,070
and verification of your workstations and servers for you,

182
00:06:26,070 --> 00:06:27,360
and this will help ensure the patches

183
00:06:27,360 --> 00:06:29,070
have been properly installed.

184
00:06:29,070 --> 00:06:31,440
Now, if you're using Linux or Mac-based systems,

185
00:06:31,440 --> 00:06:34,230
they also have built-in patch management systems too.

186
00:06:34,230 --> 00:06:37,020
For example, in Linux, you can use a package manager

187
00:06:37,020 --> 00:06:40,200
to deploy RPMs or packages of those patches to all

188
00:06:40,200 --> 00:06:41,580
of your servers and workstations.

189
00:06:41,580 --> 00:06:42,480
And the same concepts

190
00:06:42,480 --> 00:06:44,790
and principles apply like the ones we were talking about

191
00:06:44,790 --> 00:06:45,623
when using the

192
00:06:45,623 --> 00:06:48,120
Microsoft Endpoint Configuration Management tool.

193
00:06:48,120 --> 00:06:50,310
Now, in addition to conducting patch management across our

194
00:06:50,310 --> 00:06:52,440
workstations and servers, it's also important

195
00:06:52,440 --> 00:06:53,730
that we conduct firmware management

196
00:06:53,730 --> 00:06:55,500
for all of our network devices.

197
00:06:55,500 --> 00:06:57,900
After all, our network devices, like our switches

198
00:06:57,900 --> 00:07:00,240
and routers, are all running a form of software known

199
00:07:00,240 --> 00:07:02,310
as firmware on those devices to be able

200
00:07:02,310 --> 00:07:04,410
to provide the operating system to them.

201
00:07:04,410 --> 00:07:06,360
If your network devices don't contain the latest

202
00:07:06,360 --> 00:07:08,070
and most up-to-date firmware versions,

203
00:07:08,070 --> 00:07:09,600
then you could have security vulnerabilities

204
00:07:09,600 --> 00:07:12,570
and software bug that could be exploited by an attacker.

205
00:07:12,570 --> 00:07:14,670
If you look at the common vulnerabilities and exposures

206
00:07:14,670 --> 00:07:17,880
or CVE website, you'll see a long list of vulnerabilities

207
00:07:17,880 --> 00:07:20,370
that are identified in various Cisco networking devices

208
00:07:20,370 --> 00:07:22,290
as well as other brands too.

209
00:07:22,290 --> 00:07:24,420
So just like you need to patch the operating system

210
00:07:24,420 --> 00:07:26,610
of a Windows, Mac or Linux computer,

211
00:07:26,610 --> 00:07:28,410
you still need to update the operating system

212
00:07:28,410 --> 00:07:29,910
of your network devices.

213
00:07:29,910 --> 00:07:30,990
In a Cisco device,

214
00:07:30,990 --> 00:07:33,870
this operating system is known as Cisco's iOS

215
00:07:33,870 --> 00:07:36,000
or the inner network operating system.

216
00:07:36,000 --> 00:07:37,560
To update the iOS version,

217
00:07:37,560 --> 00:07:40,440
you need to flash the firmware on that networking device.

218
00:07:40,440 --> 00:07:43,170
Now, some device manufacturers like Cisco do provide

219
00:07:43,170 --> 00:07:45,540
a centralized method of conducting firmware management

220
00:07:45,540 --> 00:07:47,190
in your enterprise networks.

221
00:07:47,190 --> 00:07:50,430
For example, Cisco uses the Cisco UCS Manager

222
00:07:50,430 --> 00:07:53,130
to centralize the management of resources and devices

223
00:07:53,130 --> 00:07:54,450
and to conduct firmware management

224
00:07:54,450 --> 00:07:57,330
for server network interfaces and server devices.

225
00:07:57,330 --> 00:07:59,850
There are also third party tools like device expert

226
00:07:59,850 --> 00:08:02,490
by manage engine that allows you to upgrade, downgrade,

227
00:08:02,490 --> 00:08:04,890
and manage the configuration of the firmware on all

228
00:08:04,890 --> 00:08:06,960
of your network devices using automation,

229
00:08:06,960 --> 00:08:08,850
orchestration and scripting.

230
00:08:08,850 --> 00:08:10,620
The bottom line here is that you need

231
00:08:10,620 --> 00:08:11,910
to have firmware management in place to ensure

232
00:08:11,910 --> 00:08:13,830
that you have the right firmware versions

233
00:08:13,830 --> 00:08:15,420
loaded onto your network devices

234
00:08:15,420 --> 00:08:17,700
in order to secure your devices just like we do

235
00:08:17,700 --> 00:08:20,790
for our workstations and clients by using patch management.

236
00:08:20,790 --> 00:08:23,640
So remember, patch management is the planning, testing,

237
00:08:23,640 --> 00:08:26,190
implementing and auditing of software patches.

238
00:08:26,190 --> 00:08:28,560
Patch management is critical for providing security,

239
00:08:28,560 --> 00:08:30,660
increasing uptime, ensuring compliance,

240
00:08:30,660 --> 00:08:32,010
and improving features in your network

241
00:08:32,010 --> 00:08:34,080
devices, servers, and clients.

242
00:08:34,080 --> 00:08:36,450
To conduct patch management at scale, though, you do need

243
00:08:36,450 --> 00:08:38,280
to use either a tool, automation

244
00:08:38,280 --> 00:08:40,950
or orchestration to ensure that all your network devices,

245
00:08:40,950 --> 00:08:44,010
servers, laptops, and mobile devices remain up to date

246
00:08:44,010 --> 00:08:46,310
and patched against any known vulnerabilities.

