All components of a CDS should be regularly patched, with developers actively providing patches and updates for all code used within the CDS, including 3rd party libraries.
A CDS will often include third party libraries and other components. Any one of these could be subject to a vulnerability that would undermine the security of the CDS. Regular patching of the CDS and all 3rd party components is therefore required.
Defensive techniques
Patches and security updates should be produced for all components.
Mechanisms should be in place to identify vulnerabilities in third party libraries and produce tested security patches.
A process should be in place for urgent patching, outside of normal patch cycles.
Patches should be easy to administer to the components that make up the CDS.
Patches should be tested to ensure they do not break the system.
Patches should be cryptographically signed by the supplier and verified by the component (or system) before application.
Mechanisms should be in place to ensure only valid and correct patches are applied to the CDS. This may include controls to prevent a “downgrade” of a patch which may result in the CDS reverting to an older, more vulnerable, state.