1.2.3 Ensure updates, patches, and additional security software are installed

Information

Periodically patches are released for included software either due to security flaws or to include additional functionality.

Newer patches may contain security enhancements that would not be available through the latest full update. As a result, it is recommended that the latest software patches be used to take advantage of the latest functionality. As with any software installation, organizations need to determine if a given update meets their requirements and verify the compatibility and supportability of any additional software against the update revision that is selected.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Use your package manager to update all packages on the system according to site policy.

The following command will install all available updates for the base system:

# freebsd-update fetch install

Once the update process is complete, verify if reboot is required to load changes or not. The system will prompt for reboot.

The following command will install all available updates for the third party softwares:

# pkg update
# pkg upgrade

See Also

https://workbench.cisecurity.org/benchmarks/19044

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: Unix

Control ID: 14591c6ad52ab9d7a500338ca80a2134def39dfdbd16485863d41d4ccbf8fe3e