Which of these would be a good way to mitigate against some of the most common security misconfigurations?
- Have a patch management process that includes a task to check current vulnerability databases.
- Have a patch management process that includes a task to back up critical drives.
- Have a patch management process that includes a task to review and update configurations.
- Have a patch management process that includes a task to reboot servers monthly.
EXPLANATION
Patch Priority |
System patch distribution shall begin by: |
System patch installation/application shall be completed by: |
---|---|---|
Critical | Distribution shall begin within 72 hours of patch availability. | 100% of systems - 30 days |
High | Distribution shall begin within 5 business days of patch availability. | 100% of systems - 30 days |
Medium | Distribution shall begin within 30 calendar days of patch availability. | 100% of systems - 90 days |
Low | Distribution shall begin within 90 calendar days of patch availability. | 100% of systems - 150 days |
0 comments:
Post a Comment