OWASP SAMM recommendation #1: best-effort patching

technical7 months ago1 minute read
Picture of author Olivier Sels

Do you practice best-effort patching? This is our #1 recommendation to increase Application Security based on the OWASP SAMM model. Not only does this practice require relatively little effort to implement, omitting it will almost guarantee that your app will get exploited sooner rather than later.

A diagram to show the process of best-effort patching

Best-effort patching

Best-effort patching essentially requires you to do two things:

  • Keep a list of applications and third-party components with version information.
  • Regularly review public sources for vulnerabilities and update affected components.

Note that this practice does not talk about automation or managed processes for patching. The OWASP SAMM model is meant for organizations of all sizes. For smaller organizations, having a manual patching process is already a big improvement from having no patch process at all.

Next steps

Of course, you already knew patching was important, and you're probably already doing this today. That's why our next post will talk about basic data protections. Something almost every business is required by law to do, but many don't do correctly.

In the meantime, you can always perform a full OWASP SAMM assessment to see how your business can improve their Application Security. We developed a tool for it.
And be sure to follow our LinkedIn page to learn our newest recommendations to improve Application Security.


Follow us on

Perform a SAMM assessment

Free

Improve security

Easy to use

Related articles

A snippet of text to describe mvsp: Minimum Viable Secure Product.
The NIST CSF functions wheel: identify, protect, detect, respond and recover.
The AppSec program is a continual loop of Assess -> Plan -> Improve
business
January 30, 2023
Our mission

Secuma helps technology companies develop more secure applications. We encourage and guide the integration of security best practices in the entire Software Development Lifecycle, improving the security of your applications and stopping issues from becoming incidents.

Company

infosecuma.be
Sels Software & Security BV
Hoogputstraat 22B
3690 Zutendaal
Belgium
BE0748911858


Thank you for visting Secuma |
Pictures courtesy of Unsplash