Gartner Research

Structured Patch Management Reduces Risk and Keeps Business Alignment

Published: 01 March 2016

ID: G00291982

Analyst(s): Terrence Cosgrove

Summary

Effective patch management mitigates risk by eliminating domain-specific activities and applying standard processes across all enterprise systems. IT operations leaders can use best practices to balance the needs of security and business stakeholders, as well as their own.

Table Of Contents
  • Key Challenges

Introduction

Analysis

  • Establish a Process Lead to Set Up a Holistic Patch Management Process; Assign Patch Management Roles for Each Part of the Patching Process
  • Integrate Patching With Vulnerability, Change, Configuration and Release Management Processes
  • Include Patch Management in the Application Life Cycle; Treat Patching as Just Another Nonfunctional Change
  • Adapt Vulnerability Management and Application Compatibility Testing Processes for the Patch Management Changes With Windows 10
  • Consider Your Patch Management Needs Across All Relevant Platforms When Selecting Vendors
  • Establish Realistic Metrics That Recognize the Differences of Patching

Gartner Recommended Reading

©2020 Gartner, Inc. and/or its affiliates. All rights reserved. Gartner is a registered trademark of Gartner, Inc. and its affiliates. This publication may not be reproduced or distributed in any form without Gartner’s prior written permission. It consists of the opinions of Gartner’s research organization, which should not be construed as statements of fact. While the information contained in this publication has been obtained from sources believed to be reliable, Gartner disclaims all warranties as to the accuracy, completeness or adequacy of such information. Although Gartner research may address legal and financial issues, Gartner does not provide legal or investment advice and its research should not be construed or used as such. Your access and use of this publication are governed by Gartner’s Usage Policy. Gartner prides itself on its reputation for independence and objectivity. Its research is produced independently by its research organization without input or influence from any third party. For further information, see Guiding Principles on Independence and Objectivity.

Already have a Gartner Account?

Purchase this Document

To purchase this document, you will need to register or sign in above

Become a client

Learn how to access this content as a Gartner client.