4 ms·
Most common security mistake: Lack of a Patch Management Policy that is actually followed. Just look at WannaCry. The Patch was released March 14th and the wor
by akshatpradhan 9y ago
Most common security mistake: Lack of a Patch Management Policy that is actually followed.
Just look at WannaCry. The Patch was released March 14th and the worm was released May 12th.
That shows everybody who was compromised simply didn't have a regularly scheduled Patch Management Process in place.
From WannaCry Wikipedia page:
>A "critical" patch had been issued by Microsoft on 14 March 2017 to remove the underlying vulnerability for supported systems, nearly two months before the attack, but many organizations had not yet applied it.
>Almost all victims are running Windows 7 or newer.
Same with web apps, have a regularly scheduled Patch Management Policy in place for the Libraries, Gems, Modules, Packages, etc you use.