Check: 2.019
Windows Vista STIG:
2.019
(in versions v6 r42 through v6 r41)
Title
Security-related Software Patches are not applied. (Cat II impact)
Discussion
Major software vendors release security patches and hot fixes to their products when security vulnerabilities are discovered. It is essential that these updates be applied in a timely manner to prevent unauthorized persons from exploiting identified vulnerabilities. The Severity code may be elevated to a Category I if patches deemed Critical have not been applied.
Check Content
Verify that the site is applying all security-related patches released by Microsoft. Determine the local site method for doing this (e.g., connection to a WSUS server, local procedure, etc.). Severity Override: If any of the patches not installed are Microsoft ‘Critical’, then the category code should be elevated to ‘1’. Note: If a penetration scan has been run on the network, it will report findings if security-related updates are not applied. Then, this check may be marked as “Not Applicable”. Some applications (such as DMS and GCSS) use a system release process to keep systems current. If this is the case, then these systems should be at the current release.
Fix Text
Apply all Microsoft security-related patches to the Windows system.
Additional Identifiers
Rule ID: SV-29726r1_rule
Vulnerability ID: V-3828
Group Title: Security-Related Software Patches
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |