Annex 6.6.1
Mapped SPARTA techniques (11)
Techniques referencing this article
Patch-management procedures ensure that authentication-related fixes are applied through controlled channels; out-of-band modifications to auth logic should fail patch-integrity checks.
Security-patch management procedures determine how known code-flaw fixes are deployed to the entity's network and information systems; the deployment cadence is the metric that bounds the exploit window.
Security-patch management procedures govern the deployment of fixes to flight software once defects are identified, determining the operational dwell time before remediation.
Security-patch management procedures bound how quickly OS-layer fixes are validated, packaged and deployed to flight or ground systems running the affected kernels.
Security-patch management procedures determine the cadence at which known vulnerabilities in COTS/FOSS components are closed, the metric the technique attempts to outrun.
Security-patch-management procedures, by constraining how legitimate code is delivered, also serve as the procedural envelope that out-of-band malicious-code introduction must subvert.
Security-patch management procedures are the lever that ensures swapped or maliciously-signed update packages are detected and remediated through coherent change-management discipline rather than installed silently.
Security-patch management for SDR firmware and waveform packages is the lever that closes the SDR-compromise opportunity before it is exploited.
Security-patch management procedures govern how security updates are produced, signed and deployed to flight assets; they are the procedural envelope around the on-orbit update pipeline.
Security-patch management procedures determine how quickly hypervisor defects are deployed in flight or ground systems; deployment cadence bounds the exploit window for disclosed escape paths.
Security-patch management procedures determine how quickly publicly-known vulnerabilities are closed in the entity's systems, which is the metric the adversary's known-vulnerability reconnaissance is trying to exploit before remediation.