This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Use specific pattern version

Hi,

we're already using Sophos on our Windows Server and we now evaluate to use Sophos on our cash box systems.

The requirement from this department is to test new pattern versions in a test environment before deploying them.

I know that Sophos releases several pattern updates per day and that you should use always the latest pattern versions to be safe, but in this specific case, we have to test the pattern versions before deploying them.

The risk that a false-positive may block core components of our cashbox system and thousands of our customers can't pay in our shops is much higher than getting infected by malware because we are using multilevel firewalls, application whitelisting,...

So is it possible e.g. to test the latest pattern version on a test group for 1 day (with no automatoc update of the pattern version) and if no problems occured, deploy this version to the productive systems.

I know I can do this with software subscriptions for the scan engine. But is something like that possible for the scan engine.

Thanks.

:44171


This thread was automatically locked due to age.
Parents
  • Hello Shawn,

    an idea from my side which might help you:

    We rsync our CID to a Linux web server for our Home-Users at specific intervals (5 minutes) from our local windows SUM CIFS share.

    This system could also be deactivated and only ran manually. You could build a staging and production CID for your hardened machines, where the staging CID is set to production after tests, e.g. via Apache virtual hosts or something. Maybe a kind of clumbsy but should do the job, so the hardened endpoints stay on the tested virus definitions until you test another bunch of updated definitions.

    Kind regards, -sd

    :44181
Reply
  • Hello Shawn,

    an idea from my side which might help you:

    We rsync our CID to a Linux web server for our Home-Users at specific intervals (5 minutes) from our local windows SUM CIFS share.

    This system could also be deactivated and only ran manually. You could build a staging and production CID for your hardened machines, where the staging CID is set to production after tests, e.g. via Apache virtual hosts or something. Maybe a kind of clumbsy but should do the job, so the hardened endpoints stay on the tested virus definitions until you test another bunch of updated definitions.

    Kind regards, -sd

    :44181
Children
No Data