Purpose
The purpose of this policy is to establish standard procedures for the identification of vulnerabilities, potential areas of functionality enhancements as well as the safe and timely installation of software patches. Effective implementation of this policy shall limit the exposure and effect of common malware threats to the systems within this scope.
Policy
To reduce system vulnerability and ensure the confidentiality, integrity, and availability of SSMC’S data stored on its systems and to enhance and repair application functionality, SSMC’S computers and systems must be properly patched with the latest appropriate updates available from operating systems and / or applications vendors.
Scope
This policy applies to all Operating System software, Application software, Databases, Firmware running on Servers, Desktop computers, laptops, Network devices and any IT equipment owned and operated by Smart Salem.
Responsibilities:
- IT Director: Ensure the software patch management policy and procedure is implemented and adhered to in SSMC’s.
- Facility & Biomedical Team: Must follow the procedure described in the software management policy and ensure that their vendors are adhering to procedure too.
- Infrastructure Manager: To ensure that the policies are followed by the IT infrastructure team and IT Infrastructure vendors.
- IT Applications Manager: To ensure that the policies are followed by the IT applications team an IT applications vendors.
- Systems Administrator/ Applications Specialist: To ensure that all Operating Systems and Applications software are patched as per the policy with the coordination with the IT Infrastructure, IT Applications team, and IT Vendors.
- Network Engineer / Administrator: To ensure all the Network equipment’s and patched as per the policy with the coordination with IT Vendors.
- Database Administrator: To ensure that all the Databases are patched as per the policy with the coordination with the Applications team and IT Vendors
Procedure
The process of patch management has been developed over many years to ensure the safe deployment of relevant Operating System enhancements, Applications enhancements, bug fixes and security updates into a large organization IT system such as the SSMC’S.
The IT Department implements Patch Management Best Practice to ensure safe practices that minimize risk:
- Discover and Assess
- Identify and Test
- Evaluate and Plan
- Deploy and Remediate
- Patch Management must be prioritized based on the severity of the vulnerabilities the patch addresses. SSMC’S IT shall use the below Vulnerability categories: | Vulnerability Severity | Impact | |:-:|---| | High | A successful exploit of this vulnerability may result in catastrophic or high loss of revenue or productivity to the organization operations | | Medium | A successful exploit of this vulnerability may result in moderate loss of revenue or productivity to the organization operations | | Low | A successful exploit of this vulnerability may result in slight loss of revenue or productivity to the organization operations |
- Vulnerability assessment and system patching shall only be performed by designated IT roles. These roles are:
- Systems Engineer / Administrator /Applications Specialist
- Network Engineer / Administrator
- Database Administrator
- IT Service Desk Senior Officer / Supervisor
- All servers, desktops, laptop computers, Applications software’s, Databases, Network equipment’s and Services including all hardware and software components, must be accurately listed in the IT Department asset inventory to aid in patching efforts, for this purpose we are using Assets Management System to manage and maintain the inventory of IT assets.
- Each vulnerability alert and patch release must be checked against existing SSMC’S systems and services prior to taking any action to avoid unnecessary patching. All alerts must be checked carefully as not all patches are related to issues or actual system versions present at SSMC’S.
- All patches must be downloaded from the relevant system vendor or other trusted sources. Each patch’s source must be authenticated, and the integrity of the patch must be verified.
- All vendors provided computer or server connected with medical equipment must have severity level of High update.
- New servers and desktops must be patched to the current agreed baseline patches before coming online to limit the introduction of risk to the organization’s network.
- New software and applications must be patched to the agreed baseline when installed on SSMC’S resources to limit the introduction of risk.
- All patches must be tested prior to full implementation since patches may have unforeseen side effects. Testing shall take the form of using a clone or Test system that closely matches the SSMC’S production systems. Where there is no Test system, then a noncritical server shall be used, and the results of any patch shall be closely monitored for adverse effects.
Respective IT engineer or manager shall complete the Software Patch and Application Release Sign-off Form and obtain necessary approvals. If patching / release is major and affecting business department’s head of concerns departments must authorize patching / release process before deploying into production.
- A Rollback plan that allows safe restoration of systems to their pre-patch state must be devised prior to any patch rollout if the patch has unforeseen effects and as per the IT Backups and Restoration Policy.
- Patches shall be applied according to the IT Departments defined patching schedule. It is also required to arrange the deployment after discussing it with end users and chief officers if it affects user’s activity.
- Rollout of tested patches shall adhere to the procedure defined in the patching schedule.
- All configuration and inventory documentation must be immediately updated to reflect applied patches. This includes the following documents:
- CMDB Configuration Management database or manual records (sheet) in case if CMDB is not available.
- Audits by both Application and Infrastructure Managers shall be performed to ensure that patches have been applied as required and are functioning as expected in their respected systems.
- Exceptions:
Exceptions to the patch management policy require formal documented approval from the IT Director.
Any IT system that does not comply with policy must approved by IT Director with justification for expectation on file.
- Monitoring and Compliance
A compliance level refers to the percentage of computer devices, software and applications that have been successfully patched or otherwise remediated such that they are no longer vulnerable.
The IT Department shall endeavour to achieve 100% compliance for Operating Systems and Application Software under its management however, the following factors must be considered when setting a compliance level:
* Users that own multiple computers (which aren’t always connected and powered on).
* Employees with laptop computers that don’t log into the Company’s network.
* Computers being repaired or replaced by a hardware vendor.
* Computers registered in Active Directory that have been repurposed and/or reimaged and yet have not been removed from the directory.
For monitoring and compliance assessment the following level must be maintained:
* 95% of Servers shall be patched for the components installed on that device within 2 months of an appropriate patch being released.
* 95% of Applications shall be patched for the components installed on that device within 2 months of an appropriate patch being released.
* 90% of Network equipment’s shall be patched for the components installed on that device within 2 months of an appropriate patch being released.
* 95% of Security equipment’s shall be patched for the components installed on that device within 2 months of an appropriate patch being released.
* 95% of Workstations shall be patched for the components installed on that device within 2 months of an appropriate patch being released.
* 95% of Laptops, tablets and Mobile devices shall be fully patched for the components installed on that device within 2 months of an appropriate patch being released.
Non-Compliance
Failure to observe these guidelines may result in disciplinary action by SSMC’S management depending upon the type and severity of the violation, whether it causes any liability or financial / reputation loss to SSMC’S, and/or the presence of any repeated violation(s).
Software and Patching Baseline
| System | Platform/Software Version | Patch version / number |
|---|---|---|
| Desktop Computers, laptops, tablets | ||
| Servers, Storage and Backup Software | Windows (Windows Server 2008 – 2016) | |
| VMware, HyperV | ||
| Network Equipment (Cisco Switches, Routers, Firewall, Gateways, Load balancers etc.) | ||
| Protection software (Antivirus) | ||
| Databases (Oracle, MS SQL, Sybase, MySQL etc.) | ||
| Microsoft Office, Acrobat, | ||
| Internet browsers | ||
| CORE SS/HIS application | ||
| Scanning and Archiving application |
REFERENCES AND CROSS REFERENCES
IT Security Policy V1 IT Backups and Restoration Policy V2
APPENDIX
DEFINITIONS AND ABBERVIATIONS:
SSMC: Smart Salem Medical Center
Vulnerability: The quality or state of being exposed to the possibility of being attacked or harmed, either hardware or software
Software Patches: A patch is a set of changes to a computer program, or its supporting data designed to update, fix, or improve it. This includes fixing security vulnerabilities and other bugs, with such patches usually being called bug fixes and improving the usability or performance.
Malware: Is short for “malicious software” computer programs designed to infiltrate and damage computers without the user’s consent. “Malware” is the general term covering all the different types of threats to your computer safety such as Viruses, Spyware, Worms, Trojans, and Rootkits and so on
Exploitation: is a piece of software, a chunk of data, or a sequence of commands that takes advantage of a bug or vulnerability to cause unintended or unanticipated behaviour to occur on computer software, hardware, or something
IT Assets Management System: refers to any system that monitors and maintains IT assets like hardware and software that has a value to the information technology department and the hospital.
Roll back plan: A back-out plan is an IT governance integration approach that specifies the processes required to restore a system to its original or earlier state, in the event of failed or aborted implementation.
CMDB: Configuration Management Database contains all relevant information about the hardware and software components used in an organization's IT services and the relationships between those components. A CMDB provides an organized view of configuration data and a means of examining that data from any desired perspective.
