As we approach the holiday season I wanted to reach out to organizations to find out how they are addressing the following dilemma.
Most organizations have periods of time where changes such as patches and code fixes are not allowed. This is especially true during the holidays where the business operations of a mission-critical Web application is paramount. Despite known vulnerabilities businesses will operate with a certain level of known risk. Nothing new here - risk and risk mitigation is all a part of business and IT security isn't discrete.
With that said: How is your organization mitigating the risks of known application vulnerabilities during periods where patching and code changes are not allowed?
