• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Ethical Hacking

Wade Mackey

Ethical Hacking

MIS 5211.001 ■ Fall 2019 ■ Wade Mackey
  • Home
  • About
  • Syllabus
  • Gradebook

Microsoft and NIST partner on best patch management practices

October 12, 2019 by Rami Saba Leave a Comment

After the NotPetya ransomware attack of 2017, Microsoft conducted research into why large companies were being affected even though patches were already available.  Microsoft visited a significant number of customers and was surprised by how many challenges organizations faced with processes and standards.  They discovered many companies failed to install patches because they simply didn’t have a patch testing procedure in place.  Instead, they would wait a while and then ask an online forum if anyone has experienced any problems with the patches before applying them.  In addition, Microsoft has spoken with partners like the Center for Internet Security (CIS), U.S. Department of Homeland Security (DHS) Cybersecurity, and Cybersecurity and Infrastructure Security Agency (CISA).  This led Microsoft to team up with NIST and “build common enterprise patch management reference architectures and processes, have relevant vendors build and validate implementation instructions in the NCCoE lab, and share the results in the NIST Special Publication 1800 practice guide for all to benefit”.  They are also extending an invitation to other vendors so they can collaboratively work on addressing this problem.

Source: https://sdtimes.com/msft/microsoft-and-nist-partner-on-best-patch-management-practices/

Filed Under: Week 07: Social Engineering Tagged With:

Reader Interactions

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (55)
  • Week 01: Overview (6)
  • Week 02: TCP/IP and Network Architecture (2)
  • Week 03: Reconnaisance (7)
  • Week 04: Network Mapping and Vulnerability Scanning (4)
  • Week 05: Metasploit (9)
  • Week 06: More Metasploit (8)
  • Week 07: Social Engineering (11)
  • Week 08: Malware (19)
  • Week 09: Web Application Hacking (14)
  • Week 10: SecuritySheperd (12)
  • Week 11: Intro to Dark Web and Intro to Cloud (10)
  • Week 12: Introduction to Wireless Security with WEP and WPA2 PSK (6)
  • Week 13: WPA2 Enterprise and Beyond WiFi (11)
  • Week 14: Jack the Ripper, Cain and Able, and Ettercap (9)

Copyright © 2025 · Course News Pro on Genesis Framework · WordPress · Log in