Benefits of AWS Patch Policy over existing solution

0

We recently deployed a custom patching solution using AWS Patch Manager in the multi-account environment. This devops based solution is on lines of below solutions from AWS. This is a new landing zone environment and the patch management solution is still evolving

https://aws.amazon.com/blogs/mt/scheduling-centralized-multi-account-multi-region-patching-aws-systems-manager-automation/ https://docs.aws.amazon.com/prescriptive-guidance/latest/patch-management-hybrid-cloud/design-multi-account-region.html

Given AWS has recently launched a quick setup based approach of deploying Patch Policies (see the link below), I am wondering if this solution has any merit over what we have in place. Given our existing solution still not 100% ready, I was wondering if there is any benefit of using Patch Policies for managing multi-account patching.

https://aws.amazon.com/blogs/mt/centrally-deploy-patching-operations-across-your-aws-organization-using-systems-manager-quick-setup/

Can anyone provide some guidance here?

mj123
已提问 1 年前349 查看次数
1 回答
0

The primary benefit of Patch Polices is consolidation of custom Patch Baselines in a central Management Account. You can refer to the following workshop to learn how to deploy Patch Policies via CloudFormation StackSet templates from a DevOps pipeline rather than from Quick Setup: https://catalog.us-east-1.prod.workshops.aws/workshops/7c0ea253-6462-41cd-af76-3850c92458fa/en-US

profile pictureAWS
jgrabn
已回答 1 年前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则