3rd-Party Software 2.0: VSA 9 third-party patching

NAVIGATION  Software Management > Profiles > 3rd-Party Software 2.0

In the 9.5.9 release, VSA introduced the new version of the Software Management module ​— 2.0. The K3PP Software Catalog menu item has been renamed 3rd-Party Software 2.0.

Advantages

  • Frequent module updates thanks to native in-house technology without any third-party dependencies.
  • Reliable Windows patching, including BIOS and driver patching, using the native Microsoft Update service.
  • Better performance and reduced storage consumption on end machines.
  • A native VSA software application catalog to install, update, and uninstall third-party software.​

Limitations

  • Offline mode for OS patches should be configured separately using Microsoft WSUS. Refer to this Microsoft article.
  • Offline mode for third-party software is not supported.
  • Virus removal OS patches are not supported.
  • Several third-party applications do not exist in the software catalog. Refer to VSA 9 Software Management application catalog.

Tier-based software update system

The latest versions of software are uploaded to the catalog, a process that involves verifying software integrity and ensuring compatibility. Tier-based categorization prioritizes software updates based on their importance and impact on operations.

Tier Description Update Time Frame Applications
Tier 1 High-priority software applications essential to core business operations. They receive immediate attention and the fastest turnaround times. 1 business day • Google Chrome

• Firefox

• Microsoft Edge

• Java Runtime 8

• TeamViewer

• SmartFTP

• Any Tier 2 or Tier 3 software update with CVSS 9.0+ *
Tier 2 Standard software applications that support day-to-day activities but are not as critical as those in Tier 1. These applications are updated regularly but within a more extended time frame. 5 business days • 7-Zip

• Acrobat Reader DC

• Cisco Webex Meetings

• Foxit PDF Reader

• Microsoft Teams

• Microsoft Office / Microsoft 365

• Jabra Direct

• KeePass 2

• LastPass

• Notepad++

• Skype for Business

• SQL Server Management Studio

• Zoom

• Any Tier 3 software update with CVSS 7.0-8.9 *

Tier 3 Less critical software applications for which updates are scheduled based on available resources and demand, with the longest processing times among the tiers. 10 business days All other software

* FortiClient VPN updates are consistently processed within 10 business days.

Migration

During migration, you must migrate Scan and Analysis and 3rd-Party Software 1.0 profiles.

Deployment and Override profiles do not need to be migrated.

Auto update

NAVIGATION  Software Management > Profiles > 3rd-Party Software 2.0 > Select Profile > Software > Add

On the Add Software page, the Auto update column is displayed in the Added Software section.

  • The check box is selected when adding the latest version.
  • The check box is cleared when the latest version is not added.
  • The check box is cleared when the custom installer is added.

The auto-updated applications show this flag in the Version column in the format [version number] (auto update).

EXAMPLE  7.10.4.2 (auto update)

When applications are selected in the grid, the following actions are available:

  • Turn on auto update
  • Turn off auto update

When you click Turn off auto update and confirm the action, the specified version will be installed during deployment.

For applications with auto-update turned off, the Update action will not be displayed in the Version column.

Security update severity rating system

VSA Software Management 2.0 uses the Windows Update API to detect and install OS patches on Microsoft devices.

Microsoft breaks these updates into four severity categories: Critical, Important, Moderate, and Low.

VSA Software Management breaks these updates into two severity categories: Critical and Recommended.

Microsoft Severity Software Management Severity
Critical Critical
Critical Critical (Older than 30 days)
Important Critical
Moderate Recommended
Low Recommended

As follows is a breakdown of the four Microsoft severity categories with the corresponding VSA Software Management severity in parentheses:

For more information, refer to the Microsoft Security Update Severity Rating System.