Managing Patches

Information

You are responsible for patch management for your AMIs and live instances. We recommend that you institutionalize patch management and maintain a written procedure.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Implement processes to identify new security vulnerabilities and assign risk rankings to such vulnerabilities. At a minimum, rank the most critical, highest risk vulnerabilities as 'High'.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, RISK ASSESSMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-3, 800-53|CM-4, 800-53|CP-10, 800-53|RA-5, 800-53|SA-7, 800-53|SI-1, 800-53|SI-2, 800-53|SI-5

Plugin: amazon_aws

Control ID: 5821b7f57bccb33f4092d1ff3837e7889b9b91ad85d777455f637a2fe05a6646