Skip to main content

Audit Plan for Patch Management of Enterprise Applications

  • Conference paper
  • First Online:
IT Convergence and Security 2017

Part of the book series: Lecture Notes in Electrical Engineering ((LNEE,volume 450))

Abstract

Patch management is a risk management tool for enterprises and a key element of IT security programs. Improper patch management may lead to downtime and interruption, data leakage, penalties and fines for noncompliance with regulations, lost revenue, damaged reputation, litigation fees, etc. It is imperative for enterprises to develop, implement and monitor a well-structured patch management program. Monitoring of program implementation includes its audits. In this paper, an audit program and plan for patch management of enterprise applications is developed. Program includes common elements recommended by information security frameworks and the research community. The audit plan includes audit areas, accompanying audit objectives and tests. Finally, the audit areas, audit objectives and audit tests is mapped to applicable sections of the NIST cybersecurity framework.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 129.00
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 169.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info
Hardcover Book
USD 169.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

References

  1. Serova, E.: Enterprise information system of new generation. Electron. J. Inf. Syst. Eval. 15(1), 116–126 (2012)

    Google Scholar 

  2. MacLeod, K.J.: Patch Management and the Need for Metrics, SANS Institute Reading Room (2004)

    Google Scholar 

  3. Hall, J.: Information Technology Auditing and Assurance. South - Western Cengage Learning, Ohio (2011)

    Google Scholar 

  4. Souppaya, M., Scarfone, K.: Guide to Enterprise Patch Management Technologies. NIST, Virginia (2013)

    Book  Google Scholar 

  5. Joint Universities Computing Centre: Network Computing, Information Security Newsletter, p. 1, 23 December 2013

    Google Scholar 

  6. Hoehl, M.: Framework for Building a Comprehensive Enterprise Security Patch Management Program, SANS Institute Reading Room (2013)

    Google Scholar 

  7. Tom, S., Christiansen, D., Berrett, D.: Recommended Practice of Patch Management of Control Systems. Idaho National Library, Idaho (2008)

    Google Scholar 

  8. Mell, P., Tracy, M.C.: Procedures for Handling Security Patches. National Institute of Standards and Technology, Washington DC (2002)

    Book  Google Scholar 

  9. Blank, R.M., Gallagher, P.D.: Security and Privacy Controls for Federal Information Systems and Organizations, National Institute of Standards and Technology (2013)

    Google Scholar 

  10. Mell, P., Bergeron, T., Henning, D.: Creating a Patch and Vulnerability Management Program, National Institute of Standards and Technology (2005)

    Google Scholar 

  11. Medzich, M.: Deploying a Process for Patch Management in relation to Risk Management, SANS Institute (2004)

    Google Scholar 

  12. Ruppert, B.: Patch Management, SANS Institute Reading Room (2007)

    Google Scholar 

  13. Liu, S., Kuhn, R., Hart, R.: Surviving Insecure IT: Effective Patch Management. IT Prof. 11(2), 49–51 (2009)

    Article  Google Scholar 

  14. National Institute of Standards and Technology: Framework for Improving Critical Infrastructure Cybersecurity, NIST (2014)

    Google Scholar 

  15. Council on Cybersecurity: The Critical Security Controls for Effective Cyber Defense, SANS Institute

    Google Scholar 

  16. National Institute of Standards and Technology: Assessing Security and Privacy Controls in Federal Information Systems and Organizations, NIST (2014)

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Sergey Butakov .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2018 Springer Nature Singapore Pte Ltd.

About this paper

Cite this paper

Odilinye, L., Butakov, S., Aghili, S. (2018). Audit Plan for Patch Management of Enterprise Applications. In: Kim, K., Kim, H., Baek, N. (eds) IT Convergence and Security 2017. Lecture Notes in Electrical Engineering, vol 450. Springer, Singapore. https://doi.org/10.1007/978-981-10-6454-8_22

Download citation

  • DOI: https://doi.org/10.1007/978-981-10-6454-8_22

  • Published:

  • Publisher Name: Springer, Singapore

  • Print ISBN: 978-981-10-6453-1

  • Online ISBN: 978-981-10-6454-8

  • eBook Packages: EngineeringEngineering (R0)

Publish with us

Policies and ethics