From Application Security and Development Security Technical Implementation Guide
Part of ASDV-PL-003345
Associated with: CCI-001286
An application vulnerability management and update process must be in place to notify and provide users and administrators with a means of obtaining security patches and updates for the application.
Review the components of the application. Interview the application administrator. Have the application administrator demonstrate the application notification process that occurs when a security patch or product update is available. The process must include a brief description of the issue and any potential risks related to the issue. The process must also include information regarding the availability of the patch or update and how it can be obtained as well as any potential mitigations that can be utilized in the interim. If there is no application security patch or update notification process, this is a finding. If the application notification process does not include a brief description, information on risks, how to obtain the patch or update and any potential mitigations, this is a finding.
Provide a distribution mechanism for obtaining updates to the application. Include a description of the issue, a summary of risk as well as potential mitigations and how to obtain the update.
Lavender hyperlinks in small type off to the right (of CSS
class id
, if you view the page source) point to
globally unique URIs for each document and item. Copy the
link location and paste anywhere you need to talk
unambiguously about these things.
You can obtain data about documents and items in other
formats. Simply provide an HTTP header Accept:
text/turtle
or
Accept: application/rdf+xml
.
Powered by sagemincer