3 ms·
1) keep an asset register up to date. This would include libraries used. 2) subscribe to a service that alerts on vulnerabilities in the assets listed in 1). R
by sasas 9y ago
1) keep an asset register up to date. This would include libraries used.
2) subscribe to a service that alerts on vulnerabilities in the assets listed in 1). Run Nessus scans. License cost you a bit over $1k a year.
3) invest in a resource to maintain the register and respond to alerts. Tie them into a governance model so management are aware of risks and can divert time and money when needed to mitigate
Security is a process not a technology. Nothing I've mentioned here is sexy or advanced.