20.5 (L1) Ensure 'Operating System, Browser, and Endpoint Protection are updated'

Information

This setting ensures that the Operating System (OS), installed browser(s), and endpoint protection are updated regularly.

Ensuring that the OS and installed applications/software on a system are updated regularly reduces risk and the attack surface of the system.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Operating System - Configure the recommendations as prescribed in the audit section.

Browser - Configure the recommendations as prescribed (for the installed browser) in the audit section.

Endpoint Protection - Configure installed endpoint protection to automatically update.

Impact:

None - updating the OS, browser, and endpoint protection should have little to no impact on the system.

See Also

https://workbench.cisecurity.org/benchmarks/17610

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4, CSCv7|3.5

Plugin: Windows

Control ID: b6291dfd7a281d1709beb572bd7589de24941c8d35b890c672a2cc573f75966b