Hi, Darren H.
Thank you for very useful information.
My organization hadn't patched it since build until last year's support for 7.2.8. I had no experience with continuous maintenance and was in trouble.
> The honest answer is that "it depends". It depends on your setup, appetite to risk, ability to validate and criticality of what is in the patch.
> Approaches by organisation will vary based on the above.What my organization does is review each patch contents and decide if the cost of implementing the patch (cost including risk of failure and the cost of CVEs resolved) is worth it.If it is, we test it first.
Apparently, we need to change our validation items
I will consider it based on the opinion I got
> A simple rule of thumb my organization uses is as follows ... do not promote (or use) any patch for a month after it has been released in "production" .Wait a month.Any important issues usually get sorted in that one month period.
This is surprising. Almost matches the contents of the release list.
Thank you!
------------------------------
Masao
------------------------------
Original Message:
Sent: Thu January 30, 2020 05:55 AM
From: Darren H.
Subject: How to choose a stable patch
... One last thing.
A simple rule of thumb my organisation uses is as follows ... do not promote (or use) any patch for a month after it has been released in "production". Wait a month. Any important issues usually get sorted in that one month period.
By all means test in "development" or "staging".
------------------------------
Darren H.
------------------------------
Original Message:
Sent: Thu January 30, 2020 05:44 AM
From: Darren H.
Subject: How to choose a stable patch
Hi Masao,
This is a good thing to ask so don't feel like you need to delete the thread.
The honest answer is that "it depends". It depends on your setup, appetite to risk, ability to validate and criticality of what is in the patch.
Approaches by organisation will vary based on the above. What my organisation does is review each patch contents and decide if the cost of implementing the patch (cost including risk of failure and the cost of CVEs resolved) is worth it. If it is, we test it first.
If it helps, any method you currently have for selecting and applying any other software patches will be suitable.
What I strongly advise is not apply any patch to "production" without having performed a dry-run on a "development" environment. Experience with QRadar in the past few years (being honest), is that you get some good fixes but some more broken things.
I hope this helps.
------------------------------
Darren H.