1.2.2.1 Ensure updates, patches, and additional security software are installed

Information

Periodically patches are released for included software either due to security flaws or to include additional functionality.

Newer patches may contain security enhancements that would not be available through the latest full update. As a result, it is recommended that the latest software patches be used to take advantage of the latest functionality. As with any software installation, organizations need to determine if a given update meets their requirements and verify the compatibility and supportability of any additional software against the update revision that is selected.

Solution

Run the following commands to update all packages following local site policy guidance on applying updates and patches:

Run the following command to update the system with the available patches and updates:

# apt update

Run one of the following commands to apply the updates and patches:

# apt upgrade

- OR -

# apt dist-upgrade

Note: When running the command apt dist-upgrade that apt has a "smart" conflict resolution system, and it will attempt to upgrade the most important packages at the expense of less important ones if necessary. So, dist-upgrade command may remove some packages.

See Also

https://workbench.cisecurity.org/benchmarks/21369

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4, CSCv7|3.5

Plugin: Unix

Control ID: 2891b4c6210cd31048b09ad64befd5778b58ee2676d4ea83b7f1eb3b54220d8c