This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Use specific pattern version

Hi,

we're already using Sophos on our Windows Server and we now evaluate to use Sophos on our cash box systems.

The requirement from this department is to test new pattern versions in a test environment before deploying them.

I know that Sophos releases several pattern updates per day and that you should use always the latest pattern versions to be safe, but in this specific case, we have to test the pattern versions before deploying them.

The risk that a false-positive may block core components of our cashbox system and thousands of our customers can't pay in our shops is much higher than getting infected by malware because we are using multilevel firewalls, application whitelisting,...

So is it possible e.g. to test the latest pattern version on a test group for 1 day (with no automatoc update of the pattern version) and if no problems occured, deploy this version to the productive systems.

I know I can do this with software subscriptions for the scan engine. But is something like that possible for the scan engine.

Thanks.

:44171


This thread was automatically locked due to age.
Parents
  • Hi Cristian,

    thanks for your reply.

    I assumed it's not possible, now I'm sure.

    These systems are not connected to the internet. They are all in a separate VLAN and kind of isolated with firewalls. Additionally we do application whitelisting, hardened the os,... so we 've done a lot so far to secure these systems.

    All other systems are protected with antivirus software.

    The statement of our management is clear. If we can't test the IDEs or any other software/updates before applying them to these systems, we won't install/use it, because the risk described below is too high.

    :44175
Reply
  • Hi Cristian,

    thanks for your reply.

    I assumed it's not possible, now I'm sure.

    These systems are not connected to the internet. They are all in a separate VLAN and kind of isolated with firewalls. Additionally we do application whitelisting, hardened the os,... so we 've done a lot so far to secure these systems.

    All other systems are protected with antivirus software.

    The statement of our management is clear. If we can't test the IDEs or any other software/updates before applying them to these systems, we won't install/use it, because the risk described below is too high.

    :44175
Children
No Data