Adobe 38043740 Lockdown Guide - Page 83

Patch Management Procedures, Microsoft Security Tech Center

Page 83 highlights

Section 7: Patch Management Procedures Staying up to date with patches is essential to maintaining security on the server. The system administrator should monitor the vendors security pages for all software in use. Most vendors have a security mailing list that will notify you by email when vulnerabilities are discovered. Check the following websites frequently: Adobe Security Bulletins: http://www.adobe.com/support/security/ Microsoft Security Tech Center: http://technet.microsoft.com/en-us/security/default.aspx RedHat Security: http://www.redhat.com/security/updates/ Changelog for Apache 2.2 web server: http://www.apache.org/dist/httpd/CHANGES_2.2 To keep updated with ColdFusion 10 updates you can use the server update feature in ColdFusion administrator. Consider setting up an instance to email you when new updates are released. You should also consider following http://blogs.coldfusion.com/ which is published by the ColdFusion engineering team, Shilpi Khariwal's blog (the Security Czar on the ColdFusion engineering team) http://www.shilpikhariwal.com and finally third a third party commercial service http://hackmycf.com/ 83

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87

83
Section 7: Patch Management Procedures
Staying up to date with patches is essential to maintaining security on the server. The system
administrator should monitor the vendors security pages for all software in use. Most vendors have a
security mailing list that will notify you by email when vulnerabilities are discovered.
Check the following websites frequently:
Adobe Security Bulletins:
Microsoft Security Tech Center:
RedHat Security:
Changelog for Apache 2.2 web server:
To keep updated with ColdFusion 10 updates you can use the server update feature in ColdFusion
administrator. Consider setting up an instance to email you when new updates are released. You
should also consider following
which is published by the ColdFusion
engineering team, Shilpi Khariwal’s blog (the Security Czar on the ColdFusion engineering team)
and finally third a third party commercial service
http://hackmycf.com
/