Patch Management_AM

 Administrators

Administrators

Configuring Asset Management Module

Configuring Asset Category Using Form Builder

Configuring My Asset List Page

Custom Scheduler Jobs

Asset Masters

Configuring Location And Store

Configuring Asset Purpose

Configuring Action Attribute

Configuring Fault Type

Configuring Solution Type

Configuring Notifications and Templates

Configuring Allocation Form Template

Configuring Key Field Mapping

Configuring Data Templates

Configuring Field Display Order on Fixed Asset List Page

Software

Software Request Mapping Form

Adding/ Updating Software

License Mapping

Blacklisting Software

Configuring Software Baseline Profiles

Software Baseline Profile Mapping

Configuring Software License

License Key Mapping

Depreciation

Configuring Depreciation Formula

Configuring GAAP Depreciation

Configuring Depreciation Field Mapping

Configuring Custom Depreciation Formula

Mapping

Discovery Mapping

Configuring CMDB Mapping

Procurement Mapping

Account Mapping

Configuring Custom Hardware Variance

Mapping ServiceNow Category

Application Control

Creating and Updating Profile

Mapping Profiles

Configuring Application Control Messages

Configure Software and Executable Execution Type

Viewing Software Process List

Endpoint Compliance

Endpoint Dashboard

Viewing Endpoint Profile List

Configuring Endpoint Profile

Viewing Dynamic Endpoint

Configuring Dynamic Endpoint

Mapping Endpoint Profile

Endpoint Automation

Endpoint Automation Scripts

Endpoint Automation Scheduler

Endpoint Automation Profile Mapping

Patch Management

Viewing Patch List

Creating Asset Groups

Configuring Patches

Others

Configuring Asset Application Settings

Configuring Asset Movement

Configuring Asset Alerts

Configuring Store Threshold

Configuring Asset Scan Domain List

Configuring Local Password Management

Configuring E-mail Notifications

Configuring Asset Integration Details

Configuring Additional Discovery

Scheduling Asset Physical Verification

Configuring Product Price

Adding Software Deployment Profile

Approval Matrix

Configuring Approval Matrix

Configuring Approver Role

Mapping Approver

Deactivation Approval Matrix

Configuring Deactivation Approval Matrix

Configuring Approver

Configuring Location-Wise Approvers

SUMMIT Software Center

Using SUMMIT Patch Management, the Administrators can identify the missing patches on Assets and ensure that the Patches are installed on them at the specified time.

Patch Management Flow
Figure: Patch Management Flow

The following process is followed:

  1. The SUMMIT MS Patch Repository is maintained on the cloud.
  2. A job (SUMMIT_PatchJob.exe) is scheduled (Windows Scheduler) to download the Patch list from the cloud to On-Cloud SUMMIT Instance or On-Premise SUMMIT Instance.
  3. The Approver checks the Patch list (see: Viewing Patch List) and approves the Patches (see: Approving Patch List) for the Asset Groups (see: Creating Asset Groups).
  4. The SUMMIT Proxy Server downloads the approved Patches from Internet and saves the downloaded files in the local directory (Shared Directory).
  5. The Agents scan the Assets for missing Patches using the MS Patch Offline CAB and get information to download and install the Patch from the MS Patch File Store (see: Configuration for Patches).
  6. The Agents install the Patches if they are approved in the Approved Patches list. If an approved Patch, the Agents download the Patches from the MS Patch File Store. After Patch installed on the Assets, the patch update information is sent to the SUMMIT Proxy Server.
  7. The SUMMIT proxy Server updates the Patch update information in the database for both the On-Cloud SUMMIT instance or On-Premise SUMMIT instance. 

The SUMMIT Patch Management ensures that the Assets are scanned for network vulnerabilities, identifies the missing security patches and hotfixes, applies them and mitigates the risk. Hence, it identifies the missing patches, checks if the Patches are approved,  deploys them on the Assets, and updates the database with Patch update information. A few reports are available to provide a complete picture about Patches to the Administrator and Network teams. For more information about Patch reports, see Patch Reports.

Custom Scheduler Configuration

The Administrators need to add jobs in the Custom Scheduler for downloading the approved Patches from internet (Download Approved Patch Files) and for downloading the Offline Patch CAB files (Download Offline CAB Patch File). For more information about configuring jobs using Custom Scheduler, see SummitAI General Online Help.

Known Issues

  • No support for Driver Patch updates.
  • Some of the Patches display errors and cannot be installed.
  • The pre-requisites for Patch installation is not checked.