Is 'Patch Tuesday' Dead? - Calendar Of Updates(情報元のブックマーク数)

ついに、月例パッチ終了?!という記事。

2003年10月から毎月月例だしつづけているけど、パッチをもっと早くリリースする必要があるかもしれないとFishnetSecurityの人がいったって・・・MSが言ったんじゃないのか!?!!!
でも、確かにそうかもね。定例パッチと逐次更新パッチと両方ってのもありえるかも。Trendmicroのコンシューマー向けと、それ以外みたいに、、、

When Microsoft created Patch Tuesday in October 2003, it was a mechanism for bringing regularity and predictability to the patch release process. Prior to Patch Tuesday, Microsoft was routinely criticized for the chaotic and unpredictable process of releasing patches whenever they became available.

At some points over the last five years, dozens of patches have been released on Patch Tuesday. To have only one patch come out may seem like a milestone for Microsoft, a sign of progress that Patch Tuesday has achieved its goals and the Trustworthy Computing Initiative the sweeping program enacted by Bill Gates in 2002 to correct Microsoft’s vulnerability-ridden software has achieved its goals.

Microsoft has become more and more risk adverse and protect against liabilities to its brand, so they’re going to release patches as quickly as possible,” says Aaron Shilt, vice president of professional services at FishNet Security, one of the largest security solution providers.

www.calendarofupdates.com

コメントついてるなぁ、サンドボックス環境での検証が必要って、当たり前ですね

ただ、月例以外をメイン、月例パッチオプションにすると、月例パッチがより安定してサーバに適用できるかなぁとか思ったw
もちろん、すぐにパッチを出すためにはMS内部で人のアサインや、工数を出さないといけないのですぐには出来ないでしょうがw

The updates must be applied in a sandbox environment and tested against user configurations and applications before rollout and this takes time. If Microsoft went back to sporadic, unscheduled updates IS would be more like road repair or "painting the San Francisco bridge" (neverending). With a limited IT staff it might take significant time to "get back to the restart" and this leaves an uncomfortable "window of opportunity" for malware.

www.calendarofupdates.com

screenshot