Fork me on GitHub

BuildAndDeployment -> Patch Management: Usage of a short maximum lifetime for images

Risk and Opportunity

Risk: Vulnerabilities in running containers stay for too long and might get exploited.
Opportunity: Nightly built images are deployed at minimum every 1 day.

Usefulness and Requirements of this Activitiy

Usefullness: Medium
Required knowledge: Medium (two disciplines)
Required time: High
Required resources (systems): Low

Additional Information

Implementation hints:

OWASP SAMM VERSION 2

ISO27001 2017