How to keep track of hotfixes, patches, etc?

Although I'm a developer, my client has asked me to help them in keeping some of their servers up to date with the latest patches and hotfixes from Microsoft.

We don't want to just blindly update from Microsoft, but rather want to investigate each hotfix and patch to make sure it isn't gonna bork our servers up. 

Short of running SMS or a similiar tool, any tools available to help keep track of what patches have been applied to what server? I know this wouldn't be that hard to crank out myself, but I'd rather not mess with writing a one-off app if there is a simple program already out there.

So, any tools out there for small IT shops to help track what's been loaded on their servers?

Mark Hoffman
Thursday, August 14, 2003

Uh...I'll answer my own question; perhaps it will help someone else.

Microsoft Baseline Security Analyzer seems to be what my client is needing.

Mark Hoffman
Thursday, August 14, 2003

