Course Content
Understanding the Defence Industry Security Programming (DISP)
This topic explains the Defence Industry Security Program (DISP). Explains what DISP does for the industry and which entities may apply for DISP membership.
0/4
Conduct An Initial Review of a Cyber Security Questionnaire (CSQ)
During this topic you will be taught about the Cyber Security Questionnaire, and how to conduct an initial review of a submitted questionnaire.
0/4
Conduct A Quality Assurance (QA) Check of an Initial Assessment (IA)
During this topic you'll be taught how to carry out a Quality Assurance (QA) Check of an Initial Assessment (IA).
0/6
Entry Level Assessors Course
Please login for access. Login
About Lesson

Patching of Operating Systems 

A patch is a software update comprised of code inserted (or patched) into the code of an operating system to update, fix or improve the platform. This includes fixing security vulnerabilities. Applying patches to operating systems is critical to ensuring the security of an ICT environment and to mitigating the risk of exploitation of vulnerabilities within networks and systems. 

Recommendation – Patching Applications and Operating Systems 

It is recommended that the organisation replaces or updates applications, operating systems or hardware that are no longer supported by the vendor through security updates or patches with supported alternatives. 

It is recommended that the organisation applies patches within one month of the patch being released by a vendor. 

Built-in automatic updates alone does not satisfy this control and verification of the installation status (manually or automatically) is recommended. 

 Implementation Outcome 

Security vulnerabilities in operating systems and firmware assessed as extreme risk are patched, updated or mitigated within one month of the security vulnerabilities being identified by vendors, independent third parties, system managers or users. Operating systems for workstations, servers and ICT equipment that are no longer supported by vendors with patches or updates for security vulnerabilities are updated or replaced with vendor-supported versions.  

Join the conversation