Build and Deployment -> Patch Management: A patch policy is defined
Risk and Opportunity
Risk: Vulnerabilities in running containers stay for long and might get exploited.
Opportunity: A patch policy for all artifacts (e.g. in images) is defined. How often is an images getting build?
Required knowledge: Medium (two disciplines)
Required time: Very Low
Required resources (systems): Low
OWASP SAMM 2 Mapping: o-environment-management|B|1
ISO27001:2017 Controls Mapping: