Deploy a Patch

This section describes how to manage your Windows infrastructure’s software patch needs using the SilverBack solution. Once required patches have been identified via a Vulnerability Scan, you can deploy them.

Why Use SilverBack Patch Deployment?

Patch Deployment, part of the SilverBack Remediation Pack , is a separately purchasable option that enables you to quickly and efficiently identify required software patches and deploy them to your Windows infrastructure at any time. This ease of patch roll-out saves you time, effort and ultimately, money.

The Patch Deployment feature currently operates only on Microsoft Windows computers running single-byte character languages (English, Spanish, French, etc.). Double-byte character languages (Japanese, Russian, Korean, etc.), are unsupported.

 

The SilverBack solution includes intelligence which enables it to:

SilverBack expects to receive a Success status from the SilverStreak within one hour of starting patch deployment. If Success is not received within that time frame, the system generates an alert to notify you of the failure.

 

SilverBack can track a history of deployed patches in a report that can be scheduled. This provides a documentable audit trail tor regulatory or customer requirements compliance.

 


Deploying Patches

  1. From the Security category page click on the New Patch Deployment link to display the Add Patch Deploy form.

The Add Patch Deploy form consists of four (4) tabbed sub-forms:

Immediately deployed Patch Deployments cannot be canceled.

 

Attributes

  1. In the Attributes tab form, select the target Windows devices' parent Management Domain from the drop-down.

  2. Enter a name for the Patch Deployment into the Name field.

    The maximum size of this field is 64 characters.

  3. Optionally, you can enter a Description of the Patch Deployment.

    You can enter a description of the Patch Deployment , up to a maximum of 1024 characters. You can also enter HTML links here in the format "http://”, “https://" or "mailto:". The quotation marks are mandatory for HTML links

Options

  1. Click on the Options tab to display the Options tab form.

  2. To cause alerts to be generated if the Patch Deployment fails, click on the Generate Alerts checkbox.

    The default state is False (unchecked).

  3. If you want to change the Patch Deployment's alert Severity, select the appropriate level from the drop-down:

    The default severity is Critical.

  1. If you want to change the Patch Deployment’s timeout value, type the value (in minutes) into the Execution Timeout (Min) field.

    The default value is 60 minutes.

  2. To deploy the patches now, ensure that the Install Patch Immediately radio button is selected.

    The default setting is to deploy immediately. The system will download and install the patches when you click on the Save button.

  3. To deploy the patches at a later date, select the Schedule radio button.

    1. Then, select the desired month, day, year and time from the drop-downs.

  1. To schedule reboots of the affected Windows devices, select one of the following radio buttons:

The default setting is Reboot Immediately.

Targets

  1. Click on the Targets tab to display the Targets tab form, which consists of an expandable list of Management Domains and devices.

  2. Expand the list, then select the devices to which you want to deploy patches.

You must select one or more devices before continuing.

 

Patches

  1. Click on the Patches tab to display the Patches tab form.

This form is unpopulated until a Patch Scan has been run, and then devices have been selected in Step 2 in the Targets tab. See Performing a Security Audit for more information about running Vulnerability Scans.

 

  1. Select the patches you wish to include in the Patch Deployment.

Finishing Up

  1. If you make a mistake and wish to start again, click on the Reset button.

  2. Click on the Save button to save your work.

  1. Or, click on the Cancel button to abandon the operation without making any changes.

A confirmation dialog message displays, asking you to confirm or cancel the operation.

Immediately deployed Patch Deployments cannot be canceled.

 

  1. Click on the OK button to deploy the patches.

    1. Or, click on the Cancel button to dismiss the dialog message and return to the Add Patch Deploy form.

 


 

Related Topics