When the OS security updates are applied

We have the following software on the database servers:

Oracle Enterprise Linux 5 2 update
11g Oracle Clusterware
Oracle 11g ASM
Oracle Database 11g with RAC EA

The database serves as a repository for Application of CRM Siebel.

Our system administrator has recently applied the security fixes for Oracle Enterprise Linux (OS). What tests should be performed and by whom?

user10437903 wrote:
Can I apply the CPU of the database to the server where the updates of OS security had taken place and test only once?

Can you? Sure. It's more risky, however. If something goes wrong, you don't know if it's the patch of the database or OS patch that caused the problem, so you don't know what to push. Generally speaking, you would change rather than one thing at a time.

Since you don't have a suite of automated tests, you must balance this risk against the cost of duplication of testing effort. The most important application, more you want to control how many things are changing at the same time.

Is it true that OS and Oracle CPU security make no changes to functionality?

They should not change functionality. Does not not to say, however, that in practice an operating system security patch is not break something depends on your application special, or a database security patch is not break something who depend on you. They are relatively rare, but there is a disc no zero of something goes wrong.

I need more specific details on the TYPES of TRIALS that should occur, by whom and in what order.
I do a regression test all of the Siebel Application, which had no security patch given stressing the server database (database on different servers and Siebel) had patched OS security?
Because functional changes are not supposed to happen from security fixes, which is the fact that this level of analysis? Standard/best practices?

Like I said - it is highly dependent on the particular company you use and the application that you use. If you have an application that is essential to the maintenance of the operating business where downtime costs millions of dollars an hour, well worth doing a test of complete regression for each security patch. If you have an application that is the subject of various kinds of regulatory controls, you probably need certification that each patch has no effect on the functionality of the application. If you have a relatively low priority request that is not critical to the company, on the other hand, it might be reasonable to apply patches without tests and agree that there is a low risk that something will go wrong and the application will fail.

Different organizations plot also tests responsibilities differently. Some organizations have a dedicated test group. Some rely on developers. Some require users to test and approve the changes. Some have test analysts. Some companies may want to do a full review of each application, others can be comfortable with a simple test of surface-level that you can connect and demand seems to be upward. Some companies want to make performance / stress testing, which can include the DBA and directors Unix, any other just wanted to test the basic features.

Best practice is to establish a balance between the cost of the tests, the level of risk of the patch and the cost of downtime. What is appropriate for behind customer servers to the web site a large brokerage house, for example, is probably very different from what is appropriate for the accounting system backend for a medium-sized retailer. The consequences, financial and advertising of the former declining even for a short period are enormous - if that fails, particularly for non-critical time, you can be inconveniencing a handful of internal users.

Justin

Tags: Database

Similar Questions

Maybe you are looking for

  • Account iTunes on multiple devices

    So, my friend is using my apple on another iphone ID. but my app with on apple mail my phone gmail also will sign sound when it connect to itunes... also im wondering if it backs up on itunes with an itunes password encryption on the device. It will

  • Double timer

    Hello world! I have a problem to solve on my VI (Please find the attached photo). I need to control the flow of a pump (timered) if it receives the signal of a DI.the signal to the second timer (that of the pump flow rate) is led by a first timer tha

  • Update of security for Microsoft Office 2007

    I have Microsoft Office 2003. Windows Update recommend upgrades security for Microsoft Office 2007. Is this something for me? Best regards / Hans

  • My toshiba canvio basics3.0 1.0 TB will not back up my toshiba computer

    I have Toshiba Z830 CORE i7 with windows 7 & I'm trying to go back to Toshiba Canvio Basics 3.0 1.0 to external hard drive, but the custom of the computer recognize the external device. He appears in the devices, but is not recognized when you try to

  • Wired conection loses sight of the files on the server, but can be crazy with success

    Suddenly, while accessing the files via the wired network connection, do not see the server unless you perform a restart.  However, I can still ping the address successfully.  It's a Win 7 computer accessing a sbs2003 server and it is the only networ