|
+OPS-29.01B |
1. ÜbersichtOPS-29.01BThe cloud service provider designs, implements and maintains technical and organisational measures to manage updates to system components used to provide the cloud service that incorporate third-party or open-source libraries. This includes:1. Regularly identifying available updates and known vulnerabilities in third-party or open-source libraries used within applications; 2. Evaluating the potential impact of identified updates and vulnerabilities on the applications and the overall security posture; 3. Implementing necessary updates and patches in a timely manner to address identified vulnerabilities; and 4. Continuously monitoring applications to ensure updates are effectively applied and no known or unmitigated vulnerabilities are introduced.
1.1 Referenzen1.2 Identifizierte Anforderungen1.2 Related Regulation2. Identifizierte Anforderungen
3. Related Regulations
|