Question: You are a project manager on the Patch Management team, tasked with creating a workflow and RACI matrix for your organization's patch management process to

You are a project manager on the Patch Management team, tasked with creating a workflow and RACI matrix for your organization's patch management process to update and patch security vulnerabilities on computers. The current process is the following: Microsoft releases to the public the latest security patches on "Patch Tuesday", which is typically the 2nd Tuesday of every month. The Engineering Team of your company who is based in Europe, owns and manages a tool called System Center. After each "Patch Tuesday", the Engineering team analyzes and makes a determination on which patches are relevant to your organization, and imports the required patches from Microsoft's patch server into the System Center tool. The Engineering Team then notifies the Patch Management team, so that the Patch Management team can now use the tool to perform pilot testing to ensure that applying the patches do not break any computers. The Patch Management team will provide the Engineering team with a status update, to let them know if testing was successful or if there were issues. If issues were found during pilot testing, the Engineering team will have to review what they did and make changes in the System Center tool to fix the issues, then have the Patch Management team retest. After pilot testing is completed, the Patch Management team sends a notification to the Application Testing team to let them know that new patches will be installed on their computers for testing. The Patch Management Team then uses the System Center tool again to deploy and install the patches to the Application Testing Team's computers. The Application Testing Team then performs User Acceptance Testing (UAT), and will inform the Patch Management team if they come across any issues. If issues are reported, then the Patch Management team informs the Engineering Team, and the Engineering team will have to review what they did and make changes in the System Center tool to fix the issues. Then they must send it back to the Patch Management team to retest. If no issues are reported, the Patch Management team will then use the System Center tool to deploy and install the patches to all of the computers in the company. Both the Patch Management team and the Engineering team will track the progress of the deployment to the computers, but it is the Engineering team who will report the status every week to the Chief Information Security Officer (CISO). Part 1 (4 points) Based on the above scenario, create Patch Management Process Workflow. You can use a Workflow tool like Microsoft Visio, or a free online workflow tool such as (https://www.draw.io/). Part 2 (4 points) Based on the above scenario create a RACI matrix. (Reminder: your RACI matrix should correspond with the Process Workflow you created in Part 1) Presentation (2 points)

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related General Management Questions!