OWASP SAMM recommendation #1: best-effort patching

technical7 maanden geleden1 minuut leestijd
Picture of author Olivier Sels

Do you practice best-effort patching? This is our #1 recommendation to increase Application Security based on the OWASP SAMM model. Not only does this practice require relatively little effort to implement, omitting it will almost guarantee that your app will get exploited sooner rather than later.

A diagram to show the process of best-effort patching

Best-effort patching

Best-effort patching essentially requires you to do two things:

  • Keep a list of applications and third-party components with version information.
  • Regularly review public sources for vulnerabilities and update affected components.

Note that this practice does not talk about automation or managed processes for patching. The OWASP SAMM model is meant for organizations of all sizes. For smaller organizations, having a manual patching process is already a big improvement from having no patch process at all.

Next steps

Of course, you already knew patching was important, and you're probably already doing this today. That's why our next post will talk about basic data protections. Something almost every business is required by law to do, but many don't do correctly.

In the meantime, you can always perform a full OWASP SAMM assessment to see how your business can improve their Application Security. We developed a tool for it.
And be sure to follow our LinkedIn page to learn our newest recommendations to improve Application Security.


Vindt ons op

SAMM analyse uitvoeren

Gratis

Veiligheid verbeteren

Gemakkelijk in gebruik

Gerelateerde artikelen

A snippet of text to describe mvsp: Minimum Viable Secure Product.
The NIST CSF functions wheel: identify, protect, detect, respond and recover.
The AppSec program is a continual loop of Assess -> Plan -> Improve
business
January 30, 2023
Onze missie

Secuma helpt softwarebedrijven om veiligere applicaties te ontwikkelen. We moedigen het gebruik aan en helpen met de integratie van innovatieve oplossingen en processen uit de DevSecOps industrie. Hierdoor verbeteren we de veiligheid van uw applicaties en voorkomen we dat problemen uitgroeien tot incidenten.

Bedrijf

infosecuma.be
Sels Software & Security BV
Hoogputstraat 22B
3690 Zutendaal
België
BE0748911858


Bedankt voor je bezoek aan Secuma |
Afbeeldingen met dank aan Unsplash