Site icon 지락문화예술공작단

Windows monthly security and quality updates overview

Windows monthly security and quality updates overview

Today’s global cybersecurity threats are both dynamic and sophisticated, and new vulnerabilities are discovered almost every day. We focus on protecting customers from these security threats by providing security updates on a timely basis and with high quality.  We strive to help you keep your Windows devices, regardless of which version of Windows they are running, up to date with the latest monthly quality updates to help mitigate the evolving threat landscape.

That is why, today, as part of our series of blogs on the Windows approach to quality, I’ll share an overview of how we deliver these critical updates on a massive scale as a key component of our ongoing Windows as a service effort.

Quality and security at scale
The scale and diversity of the Windows ecosystem requires us to take a data-driven approach to quality and to leverage automation for testing, validation and distribution.  To provide the best protection, our customers’ devices need updating before vulnerabilities are publicly disclosed, a complex effort that requires a high degree of cross-industry cooperation.  To put this into perspective, each month, we update over one billion devices ranging from desktop PCs and IoT devices to servers. This includes numerous combinations of Windows versions and editions from the most current versions of Windows 10 to end-of-support versions such as Windows XP on custom support agreements.  During peak times, we update over 1,000 devices per second, allowing us to deliver the latest security and quality improvements to hundreds of millions of customers that protect them from potential vulnerabilities.  Windows monthly updates also include quality and reliability fixes based on user feedback and data we monitor, to improve the user’s overall experience.

Types of monthly updates
Windows 10 quality updates are cumulative and contain all previously released fixes to guard against fragmentation of the OS that can lead to reliability and vulnerability issues when only a subset of fixes are installed.  Most users are familiar with what is commonly referred to as “Patch Tuesday” or Update Tuesday.  These updates are published on the second Tuesday of each month, known as the “B” release (“B” refers to the second week in the month), and are the only regular monthly releases that include both new security fixes and previously released security and non-security fixes. We chose the second Tuesday at 10:00 a.m. Pacific time to give commercial customers plenty of time to test the updates and deploy them to devices.

We also release optional updates in the third and fourth weeks of the month, respectively known as “C” and “D” releases. These are preview releases, primarily for commercial customers and advanced users “seeking” updates.  These updates have only non-security fixes. The intent of these releases is to provide visibility into, and enable testing of, the non-security fixes that will be included in the next Update Tuesday release. Advanced users can access the “C” and “D” releases by navigating to Settings > Update & Security > Windows Update and clicking the “Check for updates” box. The “D” release has proven popular for those “seeking” to validate the non-security content of the next “B” release.

We also provide updates that don’t follow a standard release schedule. We refer to these as on-demand releases. They are used in atypical cases where we detect an issue and cannot wait for the next monthly release because devices must be updated immediately either to fix security vulnerabilities or to solve a quality issue impacting multiple devices.

Update quality validation
Monthly update quality is critical given the importance of the security and other fixes we regularly release at scale. As I noted in my previous blog post on the “Windows 10 quality approach for a complex ecosystem,” we use a combination of testing procedures to build and validate both feature updates and the monthly updates. Every day we build and package the latest fixes, and our engineers test and validate the fixes through a combination of the following activities:

Release information and monitoring
An integral component of an update release is the documentation we provide to keep users informed. Each release is accompanied by a knowledge base (KB) support article that communicates key release elements and issues as part of our overall transparency approach.  Once an update is released, our listening systems monitor how the update is performing across our in-market population.  To ensure users are having a good update experience, we monitor a wide array of feedback signals including:

Communications and transparencymore to come… 
We have and will continue to invest in new quality-focused features that protect Windows customers and keep them up-to-date. For the Windows 10, October 2018 Update we are providing regular updates for notable issues on the public Windows 10 update history page. We plan to improve this throughout 2019 to provide more information about our actions or partner actions to mitigate issues. I’ll have more to share on additional quality related topics in future blog posts in this series.

The post Windows monthly security and quality updates overview appeared first on Windows Blog.

Source: Windows monthly security and quality updates overview

Exit mobile version