Check: ENTD0100
Test and Development Zone A STIG:
ENTD0100
(in versions v1 r5 through v1 r3)
Title
Development systems must be part of a patch management solution. (Cat II impact)
Discussion
Major software vendors release security patches and hotfixes to their products when security vulnerabilities are discovered. It is essential that these updates be applied in a timely manner to prevent unauthorized individuals from exploiting identified vulnerabilities.
Check Content
Determine whether the organization has a patch management solution in place to apply security patches released by the vendor. If a patch management solution has not been implemented and is not functioning to update development systems with the latest patches, this is a finding. If there isn't any application development occurring in the zone environment, this requirement is not applicable.
Fix Text
Implement a patch management solution to keep development systems up to date with the latest security patches released by the vendor.
Additional Identifiers
Rule ID: SV-51298r1_rule
Vulnerability ID: V-39440
Group Title: ENTD0100 - A patch management solution is not implemented for development systems.
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |