Two-thirds of Oracle DBAs don't apply security patches
<<   January/2008   >>
Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31  

Arts
Movies
Humor
Television
Music

Business
Internet
Finance
Jobs
Investing
Economy

Computers
Software
Hardware
World
Mobile

Games
Video Games
RPGs

Health
Fitness
Medicine
Alternative

Home
Consumers
Cooking

Recreation
Travel
Food
Outdoors

Reference
Psychology
Science
Education

Regional
US
Canada
Europe

Science
NSF
Space
Technology

Society
People
Religion

Sports
Baseball
Soccer
Basketball
 
14/Jan/2008 9:00AM
Two-thirds of Oracle DBAs don't apply security patches
Complexity of task, makes admins not want to bother

January 14, 2008 (Computerworld) -- Oracle Corp. issues dozens of security patches every quarter, but that doesn't mean database administrators are necessarily implementing them.

In fact, a good two-thirds of all Oracle DBAs appear not to be installing Oracle's security patches at all, no matter how critical the vulnerabilities may be, according to survey results from Sentrigo Inc., a Woburn, Mass.-based vendor of database security products.

The results are "surprising, and to be candid, quite frightening," said Mike Rothman, president of consulting firm Security Incite in Atlanta.

Sentrigo polled 305 Oracle database administrators from 14 Oracle user groups between August 2007 and January 2008. The company basically asked the administrators two questions: whether they had installed the latest Oracle patches, and whether they had ever installed any of Oracle's security updates.

The results, which come even as Oracle is scheduled to release its next batch of quarterly Critical Patch Updates (CPU) tomorrow, showed that 206 out of the 305 surveyed said they had never applied any Oracle CPUs. Just 31 said they had installed the most recent security update from the company. In total, only one-third said they had ever installed an Oracle CPU.

The results support what Sentrigo has been hearing anecdotally for sometime, said Slavik Markovich, chief technology officer at Sentrigo. "Some database administrators don't even monitor for Oracle's CPUs. They don't even know when the CPUs come out," he said. "Sometimes even if their security department tells them to deploy it, they just ignore it," he said.

There are two major reasons for the trend, Markovich said. The first and most important is that most DBAs fear the consequences of installing a patch on a running database, he said.

"To apply the CPU, you need to change the binaries of the database," he said. "You change the database behavior in some ways that may affect application performance," he said. So applying security patches to a database typically involves testing them against the applications that feed off the database, he said. "This is a very long and very hard process to do, especially if you are in enterprises with a large number of databases and applications," he said. Applying these patches means months of labor and sometimes significant downtime, both of which most companies can't afford, he said.




Recent news in category
Image Gallery: Bill Gates Now . . . and Then
Image Gallery: Bill Gates Now . . . and Then
Complete coverage: Bill Gates Moves On

Global recent news
Jane McGonigal's Brave New Worlds
AUS - Mottram leads list of
Assn. for Fire Ecology Regional Conference 2008 in Tucson Jan 28th-31st

14/Jan/2008 9:00AM
The death of Netscape seems an inappropriate measure of the success of the Microsoft antitrust decree.

14/Jan/2008 9:00AM
Six companies have agreed to pay nearly $700,000 to settle software licensing disputes, according to the Business Software Alliance.

14/Jan/2008 9:00AM
IBM reported strong fourth-quarter earnings on Monday, beating analysts' expectations. It plans to provide its full earnings report later this week.

14/Jan/2008 9:00AM
IBM's preliminary fourth-quarter earnings report exceeded the expectations of financial analysts. But the company didn't give any credit to its business in the U.S.

14/Jan/2008 9:00AM
Former CA Inc. chief executive Sanjay Kumar has made the final $2 million payment of the $52 million he owed in restitution for his involvement in a $2.2 billion accounting fraud at the software company.

Copyright © 2006 Rootio Ltd. All rights reserved.