UL Tech Services Policies

On This Page

Desktop Patching

 Microsoft products and many third-party software applications manufacturers routinely publish updates to provide additional functionality, correct bugs in the original software or in response to potential security leaks. University Life Tech Services must make sure that all machines have such updates to provide the most secure desktop computing experience possible.

Patching Policy

In accordance with the University of Pennsylvania’s Computer Security Policy, University Life Tech Services End User Support (EUS) Team will routinely scan desktops for known missing patches and apply the missing patches in a timely manner, in accordance with the University Life Tech Services maintenance window. If a patch or patches are of extremely high priority, EUS will apply the missing patch(es) immediately to mitigate any risks.

Patching Procedure

 As of April 2016, the University Life Tech Services maintenance window is as follows: Thursday, Friday, and Saturday nights from 11 p.m. to 5 a.m. During this time, University Life Tech Services’ servers and desktops may reboot multiple times as patches and/or new software are installed.

Weekly Patching

On a daily basis, Manage Engine’s Desktop Central compares our list of downloaded patches to the provider’s (Desktop Central’s) main database and downloads all new Microsoft and third-party patches. It subsequently scans all machines that are currently on it against the main database and determines which machines are highly vulnerable (missing critical or important patches), vulnerable (missing moderate or low-priority patches), or healthy (missing no patches). This report is sent to all EUS staff and the IT Technical Director on Monday and Friday mornings around 8 a.m.

EUS will check this list on Mondays to determine desktop system health. Machines that are in the highly vulnerable category are to be remedied prior to the next patch deployment cycle on Thursday evening. Each EUS team member will be responsible for making sure all of the computers in his/her zone are rectified prior to Wednesday evening at 11:59 p.m.

Once highly vulnerable machines are remedied, vulnerable machines must then be remedied. The same procedures apply to vulnerable machines as to highly vulnerable machines. By Wednesday evening at 11:59 p.m, all machines that were vulnerable on Monday must be in a healthy state. EUS staff will provide a report to the End User Support Lead on the machines they worked on and the steps they took to resolve the issue by Wednesday at 5pm.

On Thursday morning, Desktop Central will generate a report listing all highly vulnerable and vulnerable machines and send it to the EUS Team and the IT Technical Director.