id: "SI-02(05)" title: "Automatic Software and Firmware Updates" family: "SI" family_name: "System and Information Integrity" sort_id: "si-02.05" priority: "P1" implementation_level: "system" parent: "SI-02" enhancement: True
Statement
Install {{ insert: param, si-02.05_odp.01 }} automatically to {{ insert: param, si-02.05_odp.02 }}.
Guidance
Due to system integrity and availability concerns, organizations consider the methodology used to carry out automatic updates. Organizations balance the need to ensure that the updates are installed as soon as possible with the need to maintain configuration management and control with any mission or operational impacts that automatic updates might impose (i.e., implementing a staggered deployment strategy).
Assessment Objective
{{ insert: param, si-02.05_odp.01 }} are installed automatically to {{ insert: param, si-02.05_odp.02 }}.
System and information integrity policy
system and information integrity procedures
procedures addressing flaw remediation
mechanisms supporting flaw remediation and automatic software/firmware updates
system design documentation
system configuration settings and associated documentation
records of recent security-relevant software and firmware updates automatically installed to system components
system audit records
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel installing, configuring, and/or maintaining the system
organizational personnel responsible for flaw remediation
Mechanisms implementing automatic software/firmware updates