Home > Midmarket IT Security Tips > > Will saving Microsoft patches and updates on a CD improve installation efforts?
Midmarket IT Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Will saving Microsoft patches and updates on a CD improve installation efforts?


Michael Cobb
02.05.2009
Rating: --- (out of 5)


Midmarket Security Strategies and Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


I wanted to download all the critical updates and patches from Microsoft and save them on a CD, so I wouldn't have to download them from the Internet each time I install a fresh OS. Is this a good idea, and is there a way that I can install all of these updates in one go? I cannot install some 120+ patches one by one!

When performing a fresh install of an operating system, you should certainly download all of the latest service packs and patches before you begin. By integrating any security updates into a new installation, you can prevent the system from becoming infected when it is connected to a network or the Internet for the first time. Service packs contain all the patches released up to its cut-off date. By installing a service pack, you can eliminate the need for several patches and hotfixes. If you are running a new installation some time after the latest service pack has been released, however, there will be a lot of additional patches to install at the same time as the operating system itself. Thankfully, though, you don't have to install them one at a time.

You should prepare an integrated installation, or what is commonly known as slipstreaming, where the operating system image is updated with the latest service pack, patches and hotfixes before installation. The resulting installation files create a fully updated computer in a single imaging process. If you are deploying new installations over a network, it is common practice to make the slipstreamed installation source files available on a network share. The integrated command-line option of the package installer can copy the software update files to the shared network folder. The original operating system files are then overwritten by the updated ones. For a more detailed explanation of this process, you should read "How to integrate software updates into your Windows installation source files."

If Windows is being installed on several standalone PCs, you can order slipstreamed CDs from the Microsoft Web site. I would recommend that you create your own slipstream installation, though, as you can customize it so that any specific drivers or software updates can be installed at the same time. The process involves more work initially, but overall it will save you time, particularly if you have several PCs to set up. There are a few drawbacks to slipstreaming Windows. Firstly, not all patches can be applied in this fashion. Even more annoyingly, if you discover that a certain patch is causing a problem, it cannot be removed without using an original, non-slipstreamed install CD.

Once you have installed and set up your PCs, use Microsoft's free Windows Update service, or – if your PCs are on a network -- consider the Software Update Services (SUS). The technology allows you to install a service that downloads all critical updates, security updates and service packs as they are posted to the Microsoft Windows Update Web site. The updates can then be made available to all preconfigured servers and desktops, including those that do not have Internet access. Do be aware, though, that SUS only provides security patches, critical updates, updates, update rollups and service packs, which are available from Windows Update. Device driver updates are not provided through SUS.


Rate this Tip
To rate tips, you must be a member of SearchMidmarketSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Microsoft Windows configuration and patch management
Should you disable IE ESC, or manage it in Windows servers?
Determine your Microsoft Windows patch level
Automating Microsoft Windows patch management with WSUS
Tool defeats binary diffing, automated reverse engineering of Windows security patches
Security enhancements in Microsoft Essential Business Server 2008
How to fill patch management gaps using Microsoft MBSA
Assess your security state in five steps
Adobe JBIG2 exploits being spammed, IBM warns
Inside MSRC: Microsoft updates DNS, kernel
Microsoft patches critical Windows kernel flaw

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts