Fork me on GitHub

Patch Management: A patch policy is defined

Risk and Opportunity

Risk: Vulnerabilities in running containers stay for long and might get exploited.
Opportunity: Definition of a patch policy for all artifacts in images is defined. How often is an images getting build? How long do container live maximum?

Exploit details

Usefullness: High
Required knowledge: Medium (two disciplines)
Required time: Very Low
Required resources (systems): Low

OWASP SAMM 2 Mapping: o-environment-management|B|1