OWASP SAMM recommendation #1: best-effort patching

technical1 jaar geleden1 minuut leestijd
Picture of author Olivier Sels

Do you practice best-effort patching? This is our #1 recommendation to increase Application Security based on the OWASP SAMM model. Not only does this practice require relatively little effort to implement, omitting it will almost guarantee that your app will get exploited sooner rather than later.

A diagram to show the process of best-effort patching

Best-effort patching

Best-effort patching essentially requires you to do two things:

  • Keep a list of applications and third-party components with version information.
  • Regularly review public sources for vulnerabilities and update affected components.

Note that this practice does not talk about automation or managed processes for patching. The OWASP SAMM model is meant for organizations of all sizes. For smaller organizations, having a manual patching process is already a big improvement from having no patch process at all.

Next steps

Of course, you already knew patching was important, and you're probably already doing this today. That's why our next post will talk about basic data protections. Something almost every business is required by law to do, but many don't do correctly.

In the meantime, you can always perform a full OWASP SAMM assessment to see how your business can improve their Application Security. We developed a tool for it.
And be sure to follow our LinkedIn page to learn our newest recommendations to improve Application Security.


Vindt ons op

SAMM analyse uitvoeren

Gratis

Veiligheid verbeteren

Gemakkelijk in gebruik

Gerelateerde artikelen

A snippet of text to describe mvsp: Minimum Viable Secure Product.
business
December 15, 2022

After the ransomware attacks on Antwerp and Diest, many will think: "Can this happen to us?" Here are some major red flags. If you encounter…

business
November 28, 2022

Ask any developer, manager, tester or even security professional, and they will almost certainly agree with this statement. But is it…

Onze missie

Secuma helpt softwarebedrijven om veiligere applicaties te ontwikkelen. We moedigen het gebruik aan en helpen met de integratie van innovatieve oplossingen en processen uit de DevSecOps industrie. Hierdoor verbeteren we de veiligheid van uw applicaties en voorkomen we dat problemen uitgroeien tot incidenten.

Bedrijf

infosecuma.be
Sels Software & Security BV
Hoogputstraat 22B
3690 Zutendaal
België
BE0748911858

Geregistreerd dienstverlener voor de KMO portefeuille

DV.A249876


Bedankt voor je bezoek aan Secuma |
Afbeeldingen met dank aan Unsplash