Overview
It is the chief technology officer's (CTO's) responsibility to provide a secure network environment for the Vuture application, staff, and business partners. As part of this goal, it is Vuture’s policy to ensure all computer devices (including firewalls, load balancers, routers, switches, cabling and servers) connected to Vuture networks have proper virus protection software, current virus definition libraries, and the most recent operating system and security patches installed.
Responsibility
The Infrastructure division is responsible for the overall patch management implementation, operations, and procedures. All procedures and configurations are overseen by the dedicated security team. While safeguarding the network is every user's job, Infrastructure is the division that ensures all known and reasonable defences are in place to reduce network vulnerabilities while keeping the network operating. This responsibility includes the tasks detailed below.
Backend Infrastructure
Amazon (AWS) maintain the physical backend of the Vuture network. This counts for, cabling, switches, routers, firewalls, load balancers and servers.
Front End Infrastructure
The front end infrastructure consists of the application servers and the Vuture front end. All application servers are based on Microsoft Windows Server 2019 or later. These operating systems require monthly updates which are managed and maintained by the Vuture Infrastructure team. Patching is implemented during off peak hours on the last Sunday of the month.
Monitoring
The Infrastructure and security team monitor security mailing lists, review vendor notifications and websites, and research specific public websites for the release of new patches. Monitoring will include, but not be limited to, the following:
- Scanning the Vuture network to identify known vulnerabilities.
- Identifying and communicating identified vulnerabilities and/or security breaches to the Vuture chief technology officer (CTO)
- Monitoring notifications and websites of all vendors that have hardware or software operating on the Vuture network.
Review and evaluation
Once alerted to a new patch, the security team will review categorize the criticality of the patch according to the following:
- Emergency -- an imminent threat to the Vuture network
- Critical -- targets a security vulnerability
- Not Critical -- a standard patch release update
- Not applicable to the Vuture environment
Regardless of platform or severity, all patch releases will follow a defined process for patch deployment that includes assessing the risk, testing, scheduling, installing, and verifying.
Risk assessment and testing
The infrastructure team will assess the effect of a patch to the Vuture infrastructure prior to its deployment. The department will also assess the affected patch for criticality relevant to each platform (e.g., servers.)
If the security team categorizes a patch as an Emergency, the department considers it an imminent threat to the Vuture network. Therefore, Vuture assumes greater risk by not implementing the patch than waiting to test it before implementing.
Patches deemed Critical or Not Critical will undergo testing for each affected platform before release for implementation. The Infrastructure team will expedite testing for critical patches.
Notification and scheduling
Infrastructure management must approve the schedule prior to implementation. Regardless of criticality, each patch release requires the creation and approval of a request for technical change (RTC) prior to releasing the patch. Vuture’s (CTO) will decide when notifying staff is necessary.
Implementation
The following time differences clarify the periods deemed as peak and non-peak based on client activity time.
All times are data centre local times
US (N. Virginia)
UK (London)
Europe (Frankfurt)
Canada (Montréal)
Australia (Sydney)
- Peak times: 06:00 - 21:59
- Non-Peak Times: 22:00 – 05:59
The infrastructure team will deploy Emergency patches within eight hours of availability. As Emergency patches pose an imminent threat to the network, the release may proceed testing. In all instances, the department will perform testing (either pre- or post-implementation) and document it for auditing and tracking purposes.
Auditing, assessment, and verification
Following the release of all patches, Infrastructure staff will verify the successful installation of the patch and that there have been no adverse effects.
User responsibilities and practices
It is the responsibility of each user -- both individually and within the organization -- to ensure prudent and responsible use of computing and network resources.