This paper is from the SANS Institute Reading Room site. Reposting is not permitted without express written permission. Enforcing Policy at the Perimeter The rapid deployment of security patches and anti-virus updates has become a basic need within most IT organizations. The time between the disclosure of a vulnerability and its exploitation continues to decrease while vulnerabilities are becoming easier to exploit and are increasingly severe. Locally enforcing security policy on a large number of computers can be a challenge but keeping remote (VPN or dial-up connected) computers up to date can prove even more difficult. This case study examines some options available... Copyright SANS Institut