Fork me on GitHub

BuildAndDeployment -> Patch Management: A patch policy is defined

Risk and Opportunity

Risk: Vulnerabilities in running containers stay for long and might get exploited.
Opportunity: A patch policy for all artifacts (e.g. in images) is defined. How often is an image rebuilt?

Usefulness and Requirements of this Activitiy

Usefullness: High
Required knowledge: Medium (two disciplines)
Required time: Very Low
Required resources (systems): Low

Additional Information

OWASP SAMM VERSION 2

ISO27001 2017