Check: SRG-APP-000454-UEM-000328
Unified Endpoint Management Agent SRG:
SRG-APP-000454-UEM-000328
(in version v1 r0.1)
Title
The UEM server must remove old software components after updated versions have been installed. (Cat II impact)
Discussion
Previous versions of software components that are not removed from the information system after updates have been installed may be exploited by adversaries. Some information technology products may remove older versions of software automatically from the information system.
Check Content
Verify the UEM server removes old software components after updated versions have been installed. If the UEM server does not remove old software components after updated versions have been installed, this is a finding.
Fix Text
Configure the UEM server to remove old software components after updated versions have been installed.
Additional Identifiers
Rule ID: SRG-APP-000454-UEM-000328_rule
Vulnerability ID: SRG-APP-000454-UEM-000328
Group Title: SRG-APP-000454-UEM-000328
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-002617 |
Remove previous versions of organization-defined software components after updated versions have been installed. |
Controls
| Number | Title |
|---|---|
| SI-2(6) |
Removal of Previous Versions of Software and Firmware |