1.2.2.1 Ensure updates, patches, and additional security software are installed

Information

Security vulnerabilities and functional improvements are regularly addressed through software updates and patches.

Unpatched software can expose systems to known vulnerabilities that may be exploited by attackers. It is recommended that operating system updates be performed on enterprise assets through automated patch management on a monthly, or more frequent, basis.

Solution

Use your package manager to update all packages on the system according to site policy.

The following command will install all available updates:

# dnf update

Once the update process is complete, verify if reboot is required to load changes.

dnf needs-restarting -r

See Also

https://workbench.cisecurity.org/benchmarks/23602

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4, CSCv7|3.5

Plugin: Unix

Control ID: 2010ef2f00e33f0164f80a6fc54faa54634f2bb931480cab8176eabe5091e546