7.5 Ensure that the latest OS Patches for all Virtual Machines are applied

Information

Ensure that the latest OS patches for all virtual machines are applied.

Rationale:

Windows and Linux virtual machines should be kept updated to:

Address a specific bug or flaw

Improve an OS or application's general stability

Fix a security vulnerability

The Azure Security Center retrieves a list of available security and critical updates from Windows Update or Windows Server Update Services (WSUS), depending on which service is configured on a Windows VM. The security center also checks for the latest updates in Linux systems. If a VM is missing a system update, the security center will recommend system updates be applied.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Follow Microsoft Azure documentation to apply security patches from the security center. Alternatively, you can employ your own patch assessment and management tool to periodically assess, report and install the required security patches for your OS.



Default Value:

By default, patches are not automatically deployed.

See Also

https://workbench.cisecurity.org/files/3459

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4

Plugin: microsoft_azure

Control ID: 64439f6bd3d64c2d278b565ed816c252588cbc846d171032192e7f6074cd1faa