Security Patch Management - Server
Security Patch Management (SPM) is used to deploy security related Software Updates on a scheduled basis to Windows-based servers. On the second Tuesday of every month, the packages are updated with all currently approved patches for each operating system (listed below). The packages can contain updates for the operating system, or for applications such as Internet Explorer, Windows Media Player, IIS, SQL Server, etc.) which may require patches.
You will not see a notification on your server when updates are available. By default the updates are not applied immediately, although you may manually install them prior to the package becoming mandatory. When Security Patches are delivered, you normally have a three day grace period before the patch must be installed. At the end of the grace period, the patch implementation becomes mandatory (typically the second Friday of the month).
Security Patches do not take effect on a system until it is rebooted. Machines that have additional software installed may also need new patches immediately. You may request an exemption for your server by following the Exception Request Process listed below.
The patch package may require several reboots to completely update a system. The SPM environment will not patch a system if it detects other tasks waiting to be implemented on the next restart. The SPM application will force the restart, and wait for the next scheduled run to implement the pending patches. There have been instances where a machine has restarted up to 5 times before all of the pending operations have completed, allowing the applicable patches to install.
The default behavior is to postpone the install until the grace period expires. The grace period provides the time for you to install the updates at your convenience, before they are automatically installed. If the patches are installed prior to the end of the grace period, your server will not be affected during the standard Friday outage window.
To launch the Patch Installer manually through your servers Advertised Programs:
Click Start, Settings, Control Panel.
Double-click on Run Advertised Programs.
Select the appropriate Security - PSFT Security Update (XXXXX) for your system from the "Program Name" window, and click Run. (XXXXX represents the version of Windows Server and Service Pack for your server.)
| Windows 2000 Server | Win2Ksp1, Win2Ksp2, Win2Ksp3, Win2Ksp4 |
| Windows 2003 Server | Win2K3gold |
Once the patches are installed, Patch management becomes a background task again, until the next release of patches or a change to the server’s installed software takes place.
Exceptions for patch management must be submitted via NorthStar and approved by the Information Technology Security Office. Log the NorthStar ticket as follows:
Launch NorthStar and log in, if necessary. For more information about launching NorthStar, see Eureka! document 70001 — How to create a ticket in Northstar.
On the left side of the screen, click on the Log Service Ticket link.
On the contact screen, make sure the information is current and indicate how you would like to be contacted if there are any questions.
Click Next.
Choose Other Service Request and click Next.
Select Network from the dropdown list, and answer the Operating System and Connection Type questions.
Enter Patch Management Exception Request in the Subject field.
Click on the Finish button.
Return to the top of this document.
Created by the PeopleSoft Knowledge Management Team.
Copyright © 2004
All rights reserved.
Created: pg 11/26/2003
Revised: pmg 08/05/2004