GAO report: U.S. agencies need better patch management

By

Federal agencies need to improve their software patch management, according to U.S. General Accounting Office (GAO) report released Wednesday.

A review of 24 agencies showed that they are implementing common practices for effective patch management, including system inventories and infosec training, but aren't consistently performing other practices such as risk assessments and testing all patches before deployment, the report said.


A government-wide centralized patch management service could help agencies implement selected patch management practices, according to the GAO, which serves as the investigative arm of Congress.

The GAO recommended that the director of the Office of Management and Budget provide more refined information on patch management practices and determine the feasibility of providing selected centralized patch management services.

www.gao.gov

 

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Phishing attack nets enormous npm supply chain compromise

Phishing attack nets enormous npm supply chain compromise

"VoidProxy" PhishKit targets Google and Microsoft users

"VoidProxy" PhishKit targets Google and Microsoft users

Apple adds "mercenary spyware" protection to new A19 chip

Apple adds "mercenary spyware" protection to new A19 chip

VicRoads to phase out passwords in favour of passkeys

VicRoads to phase out passwords in favour of passkeys

Log In

  |  Forgot your password?