Automated staged patch and policy management
A security information management system is described, wherein client-side devices preferably collect and monitor information describing the operating system, software, and patches installed on the device(s), as well as configuration thereof. A database of this information is maintained, along with data describing vulnerabilities of available software and associated remediation techniques available for it. The system exposes an API to support security-related decisions by other applications. For example, an intrusion detection system (IDS) accesses the database to determine whether an actual threat exists and should be (or has been) blocked.
1 . A system of networked computers programmed effectively to:
make a change to a first set of computers, including at least one computer, where the change is selected from the change group consisting of
applying a patch,
changing a policy setting, and
changing a configuration setting;
wait a first amount of time;
if affirmative cancellation has not occurred by the end of the first amount of time, automatically making the change to a second set of computers;
where the first set and the second set each comprise at least one computer.
2 . The system of claim 1 , wherein the networked computers are programmed effectively to:
wait a second amount of time after making the change to the second set of computers;
if affirmative cancellation has not occurred by the end of the second amount of time, automatically making the change to a third set of computers;
where the third set comprises at least one computer.
3 . The system of claim 1 , wherein the first set comprises at least two computers.
4 . The system of claim 1 , wherein the second set comprises at least two computers.