Lumension® Endpoint Management and Security Suite
Patch and Remediation


Automatically identify and patch vulnerabilities quickly across heterogeneous operating systems, applications and endpoint configurations

Patch Management Business Issues and Challenges

As IT environments have become increasingly complex, supporting virtual, distributed, and disparate platforms, companies must ensure that they maintain control of their endpoints.

Ensuring secure and standard endpoint configurations and patch management for third party applications and operating systems is paramount to reducing IT risk and improving endpoint operations.


With the browser fast-becoming the new corporate desktop and third party applications being heavily targeted by cybercriminals it has become more challenging to effectively mitigate IT risk exposures across today's dynamic IT environments. In fact, the number one security priority listed by the SANS Institute is patching "client-side software"1.

To ensure that systems remain configured per policy and rapidly remediated against the growing list of application and OS vulnerabilities, a solution is needed that automates discovery, assessment and remediation for heterogeneous environments and alerts busy IT administrators to issues proactively so they can address them immediately.

Overview

Lumension Endpoint Management and Security Suite delivers an end-to-end suite of solution capabilities across endpoint operations, security, compliance and IT risk management to reduce complexity, optimize TCO, improve visibility and deliver control back to IT.

Lumension Endpoint Management and Security Suite: Patch and Remediation, which is the worldwide market share leader in patch management solutions, provides rapid, accurate and secure patch management for applications and operating systems, allowing you to proactively manage threats and IT risk even in the most complex of IT environments. This optimization is achieved by automating the patching process from vulnerability identification to patch collection, distribution, remediation and verification reporting. Lumension Patch and Remediation significantly reduces the exposure to cybercriminal and malware risk while decreasing the cost of endpoint operations and compliance reporting requirements.

  • A single, intuitive management console for easy patch and remediation administration across multiple platforms - Windows, Unix, Linux and Mac OS.
  • The industry’s broadest third party vulnerability content available including the largest repository of Adobe vulnerability content.
  • Integrated asset discovery for full network visibility and continuous control across both physical and virtual environments.
  • Automated policy baselines to ensure that patches, configurations, remediations, and other tasks are continuously enforced.
  • Extensibility and customization via Lumension Content Wizard including power policy management, software deployment and removal, desktop configuration templates and custom task scripting.
  • Enhanced Wake-on-LAN to provide complete visibility and control over powered down systems and ensure that critical patches and software updates are successfully deployed. When used in conjunction with Lumension Content Wizard, power management polices and efficient patch management with maximum energy efficiency can be attained.
  • Power management reporting to effectively demonstrate the value of reduced power consumption and to use this information to apply for potential power savings rebates from your local power company.*
  • IT risk management integration via Lumension Risk Manager to automatically assess controls and potential deficiencies for IT risk management prioritization and compliance reporting.

* This is a separately licensed capability available through Lumension Patch and Remediation.


How it Works

image 2
  • 1. Discover - Gain complete visibility of your heterogeneous network environment. Proactively discover all of your IT assets, both managed and unmanaged, through in-depth scans and flexible grouping and classification options.
  • 2. Assess - Proactively identify known issues before they can be exploited. Perform a deep analysis and thorough OS, application and security configuration vulnerability assessments.
  • 3. Prioritize - Focus on your most critical security risks first.
  • 4. Remediate - Automatically deploy patches to an entire network. Simplify the process of maintaining a secure environment by continuously monitoring, detecting and remediating policy-driven environments across all major platforms and applications.
  • 5. Report - Gain a holistic view your environmental risk. Access a full range of operational and management reports that consolidate discovery, assessment and remediation information on a single management console.

Features & Benefits

Key Product Features Benefit
Integrated Endpoint Management Console
  • Features Web-, role- and workflow-based navigation to simplify and optimize endpoint operations. Seamlessly integrates with other Lumension Endpoint Management and Security Suite product modules.
Simplifies Administration of Patch Management and Other Endpoint Management and Security Tasks
  • Reduces administrative burden with a single, intuitive management console for easy patch and remediation administration across multiple platforms and many applications.
Automated Discovery and Assessment of IT Assets
  • Provides comprehensive understanding of security posture for inventory and management of both physical and virtual environments via in-depth assessment of vulnerabilities, patch status, security configurations, installed software, and hardware inventory.
  • Discovers both managed and unmanaged devices and provides swift agent deployment to any unmanaged assets.
Consolidates Visibility and Lower TCO
  • Collects device, security and configuration information to provide consolidated visibility and lower TCO.
  • Ensures visibility and control of both physical and virtual environments with effective management at a significantly reduced TCO.
Single Solution for Heterogeneous Environments
  • Vulnerability audits and remediation with wide support across major OS platforms (Windows, including Windows 7 and Server 2008 R2; Linux; MacOS; Sun Solaris; HP; etc.), POSIX and infrastructure devices, as well as third party applications, including Adobe software — all from one single console.
  • Vulnerability audits include security configurations, OS and application vulnerabilities, null passwords, patch-level related vulnerabilities, known hacking tools, malware, common worms, and P2P software checks.
Provides a Consolidated, Single Tool To Meet All Your Patching Needs
  • Enforces corporate patch policies regardless of the endpoint platform or applications.
  • Optimizes IT operations and provides an improved security posture and reduced TCO via a broad vulnerability assessment and remediation database.
  • Eliminates software-defect vulnerabilities per policy on all platforms.
Continuous Policy Enforcement of Patches, Remediations and Configurations
  • Automatically enforces patches, configurations, remediations and other custom and repetitive tasks.
  • Baseline policies can be easily exported and applied across multiple groups and servers for consistency.
Enhances Security Posture and Lowers TCO
  • Ensures that patches, configurations, remediations and other custom and repetitive tasks are continuously and automatically enforced.
  • Simplifies the recreation of previous mandatory baseline policies and ensures consistency across the network.
Diverse, Flexible Reporting
  • Provides detailed information across the patch and remediation management process, including agent policy status, vulnerability deployments, asset inventory and more.
Provides Comprehensive Visibility
  • Delivers insight into the security status of the organization.
Ensures Audit Readiness
  • Enables rapid response to internal or regulatory compliance requirements.
Highly Scalable for Distributed Environments
  • Ensures complete coverage for the largest worldwide networks with high-availability topologies and n-tier distribution architecture. Packages are cached locally, minimizing network traffic and optimizing bandwidth utilization.
Adapts to Your Growing Business
  • Leverages your current network infrastructure in order to reduce TCO from day one of implementation through the life of the subscription.
  • Adapts to various organizational setups, so you can always integrate the scanner into new business structures.
  • Ensures inventory and management of both physical and virtual environments from one consolidated console.
Role- and Policy-Based Administration
  • Enables the Patch Management Administrator to delegate/ approve patch management activities/ information across multiple employees, based on the employee’s role or security level.
  • Ensures that all systems meet a mandatory baseline policy – a key aspect of corporate security and regulatory compliance.
Enforces Compliance In Your Organization
  • Enables you to set specific policy and enforcement for each group in the enterprise.
  • Provides maximum policy flexibility with automated enforcement, saving both time and effort by IT staff.
Increases Productivity
  • Significantly improves productivity while maintaining security.
Open Architecture
  • Supporting open standards and multiple sources of content, Lumension Patch and Remediation delivers a customizable and diverse platform for operational security management.
  • Seamlessly manages third party vendor content and automatically detects and obtains prerequisite patches.
Provides a Consolidated, Single Tool To Meet All Your Patching Needs
  • Single tool's extensibility addresses the needs of customers and provides flexibility to easily accommodate new software and initiatives as they arise.
  • Automates the management and reporting of Lumension and third party licensed content and prerequisite patches without complex or manual credentials management.
Extensible, Modular Agent Architecture
  • Resilient, lower overhead agent with scalable architecture to secure on- and offline systems.
  • Provides easy agent install and uninstall capabilities.
Provides Comprehensive On- and Offline Protection
  • Protects laptops, servers, and desktops that are often disconnected from the network and reduces network bandwidth usage.
  • Resilient agent offers self-monitoring and recovery capabilities for increased security.
Enhanced Wake-on-LAN
  • Enables "wake now" capability for specific devices at any given time to deploy highly critical patches or urgent software updates.
Improves Security Posture for Offline Machines While Reducing IT Power Consumption
  • Eliminates blind spots in ongoing network maintenance and ensures that offline machines receive critical patches and software updates.
  • Ensures the attainment of maximum energy efficiency when used with power policies via Lumension Content Wizard.
Directory Services Integration
  • Dynamic creation of groups based on existing Microsoft Active Directory environments with cascading inheritance for agent policy, mandatory baseline and user permissions.
Saves Time and Cost
  • Saves time and reduces TCO by integrating with Active Directory which eliminates the need to recreate the logical organization of systems.
Automated Agent Distribution
  • Automated deployment of the Lumension remediation agent to unmanaged (rogue) computers.
Saves IT Operations Time and Effort
  • Ensures maximum coverage and protection, with minimal time and effort required by IT operations.
Automatic Notifications
  • E-mail alerts can be sent to administrators to notify them of a variety of issues, including subscription or remediation failures, upcoming license expiration and more.
Improves Security
  • Improves security through the timely response to issues.
Improves Productivity
  • Improves administrative productivity through proactive, automated alerts.
Flexible Operating Hours
  • Administrators can define specific days and intervals of time during which the agent can communicate with the server and perform operations, in granular half hour increments
Ensures No Downtime or Disruptions
  • Minimizes business disruptions and thus improves the productivity of the organization.
Flexible Group Management
  • Creates custom computer groups based on the enterprise’s needs.
  • Allows the administrator to represent multiple layers of geographical or organizational structure within the solution.
  • Hierarchical "Nested" Grouping.
Increases Deployment Accuracy and IT Efficiency
  • Enables you to increase deployment accuracy and IT efficiency by employing an organized approach via custom groups.
Increases Productivity
  • Reduces agent and group configuration efforts through more efficient creation and management of agents within groups.
Improves Policy Management
  • Facilitates the deployment of group-specific patches according to your corporate policy.
Key Indicator Dash Board
  • Enables creation of a custom dash board for the most critical information in order to highlight the success of your organization's patch management process from a list of 8 key indicators.
Provides Visibility Into Real-Time Patch Status & Overall Security Posture
  • Provides an informative snapshot of current patch status in order to report to executive management.
Multi-Patch Deployments
  • Delivers multiple patches to multiple computers in one distribution.
Reduces IT Costs
  • Simultaneously eliminates multiple vulnerabilities are simultaneously eliminated while minimizing IT costs.
Subscription Service
  • Automatic and secure identification and notification of the latest patch vulnerabilities across multiple platforms and applications.
Saves IT Operations Time and Effort
  • Eliminates the cost of manually monitoring, acquiring and staging patches for multiple platforms and applications throughout the enterprise.
Enhances Your Security Posture
  • Ensures systems stay patched and are automatically updated.
  • Ensures unauthorized packages are not able to enter your network.

Requirements

Minimum Requirements - Server

Requirements Version
Hardware A dual-core processor (any speed)
1 GB RAM
32 GB of available disk space
Operating System Windows Server® 2003, Web Edition with SP2 or later (x86)
Windows Server 2003, Standard Edition with SP2 or later (x86)
Windows Server 2003, Enterprise Edition with SP2 or later (x86)
Microsoft Windows Server 2003 R2, Web Edition with SP2 or later (x86)
Windows Server 2003 R2, Standard Edition with SP2 or later (x86)
Windows Server 2003 R2, Enterprise Edition with SP2 or later (x86)
Windows Server 2008, Web Edition (x86/x64)
Windows Server 2008, Standard Edition (x86/x64)
Windows Server 2008, Enterprise Edition (x86/x64)
Microsoft Windows Server 2008 R2, Web Edition (x64)
Microsoft Windows Server 2008 R2, Standard Edition (x64)
Microsoft Windows Server 2008 R2, Enterprise Edition (x64)

Note: Lumension Endpoint Management and Security Suite must be installed on an English operating system using any English locale (en-US, en-UK, en-CA, and so on) in its default configuration.

Web server Microsoft® Internet Information Services (IIS) 6.0 or later.
.NET Framework Microsoft .NET Framework version 3.5

Note: If not present, Microsoft .NET Framework 3.5 is installed with Lumension Endpoint Management and Security Suite.

Web browsers Microsoft Internet Explorer 7.0 or greater
Mozilla®Firefox® 3.0 or greater.
DB Server SQL Server 2005, Express Edition with SP3 (x86)
SQL Server 2005, Standard Edition with SP3 (x86)
SQL Server 2005, Enterprise Edition with SP3 (x86)
SQL Server 2008, Express Edition (x86)
SQL Server 2008, Standard Edition (x86/x64)
SQL Server 2008, Enterprise Edition (x86/x64)

Supported database servers can be installed in the following locations relative to the Lumension Endpoint Management and Security Suite server:

  • Locally in named instances installed by Lumension Endpoint Management and Security Suite.
  • Locally in named or default instances that are preexisting.
  • Remotely in named or default instances that are preexisting.

Note: If an instance of SQL Server is not present on your target server, SQL Server 2008, Express Edition with SP1 is installed with Lumension Endpoint Management and Security Suite (if you are not using a remote instance of SQL Server)


Agent Coverage - Supported Client Operating Systems

Operating System Version/Edition Architecture
Apple Mac OS X 10.3 - 10.5 x86 (Intel)/PowerPC
CentOS 4-5 X86
X86_64
HP-UX 11.11 - 11.31 64 bit PA-RISC
IBM AIX 5.1 - 5.3 PowerPC
Microsoft Windows 2000 All
(excluding Datacenter editions)
x86
Microsoft Windows Server 2003 All
(excluding Datacenter editions)
x86
X86_64
Microsoft Windows XP Professional
(excluding Home, Media Center and Tablet PC editions)
x86
X86_64
Microsoft Windows Vista All (excluding Home and Starter editions) x86
X86_64
Microsoft Windows 7 Professional
Enterprise
Ultimate
X86
X86_64
Microsoft Windows Server 2008 All (excluding Core and Datacenter editions) x86
x86_64
Microsoft Windows Server 2008 R2 Web
Standard
Enterprise
X86
X86_64
Novell SUSE Linux 9 - 11 x86
x86_64
Oracle Enterprise Linux 4-5 X86
X86_64
Red Hat Enterprise Linux 3.0 – 5.x (Enterprise AS, ES, WS) x86
x86_64
Sun Solaris 8 – 10 SPARC
x86
x86_64