id: "SI-02(05)" title: "Automatic Software and Firmware Updates" family: "SI" family_name: "System and Information Integrity" sort_id: "si-02.05" priority: "P1" implementation_level: "system" parent: "SI-02" enhancement: True


Statement

Install {{ insert: param, si-02.05_odp.01 }} automatically to {{ insert: param, si-02.05_odp.02 }}.

Guidance

Due to system integrity and availability concerns, organizations consider the methodology used to carry out automatic updates. Organizations balance the need to ensure that the updates are installed as soon as possible with the need to maintain configuration management and control with any mission or operational impacts that automatic updates might impose (i.e., implementing a staggered deployment strategy).

Assessment Objective

{{ insert: param, si-02.05_odp.01 }} are installed automatically to {{ insert: param, si-02.05_odp.02 }}.

System and information integrity policy

system and information integrity procedures

procedures addressing flaw remediation

mechanisms supporting flaw remediation and automatic software/firmware updates

system design documentation

system configuration settings and associated documentation

records of recent security-relevant software and firmware updates automatically installed to system components

system audit records

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel responsible for flaw remediation

Mechanisms implementing automatic software/firmware updates