A6
CE Willow
Security Update Management
Keeping software up to date. Willow adds CVSSv3 scoring as an explicit threshold trigger, extends scope to 'vulnerability fixes', and adds A6.3.1 to list unlicensed/unsupported software.
16 questions
1 new in Willow
A6.1
A6.2
A6.2.1
A6.2.2
A6.2.3
A6.2.4
A6.3
A6.3.1
A6.4
A6.4.1
A6.4.2
A6.5
A6.5.1
A6.5.2
A6.6
A6.7
Are all operating systems on your devices supported by a vendor that produces regular security updates and vulnerability fixes?
yesno
Is all the software on your devices supported by a supplier that produces regular vulnerability fixes for any security problems?
yesno
Please list your internet browser(s).
list
Please list your malware protection software.
list
Please list your email applications installed on end user devices and servers.
list
Please list all office applications that are used to create organisational data.
list
Are any of the in-scope software or cloud services unlicensed or unsupported?
yesno
If yes to A6.3, please list the unsupported or unlicensed software or cloud services.
list
New
Are all high-risk or critical security updates and vulnerability fixes for operating systems and router and firewall firmware installed within 14 days of release?
yesno
Are all updates applied for operating systems by enabling auto updates?
yesno
Where auto updates are not being used, how do you ensure all high-risk or critical security updates and vulnerability fixes of all operating systems and firmware on firewalls and routers are applied within 14 days of release?
text
Are all high-risk or critical security updates and vulnerability fixes for applications (including any associated files and extensions) installed within 14 days of release?
yesno
Are all updates applied on your applications by enabling auto updates?
yesno
Where auto updates are not being used, how do you ensure all high-risk or critical security updates of all applications are applied within 14 days of release?
text
Have you removed any software installed on your devices that is no longer supported and no longer receives regular updates or vulnerability fixes for security problems?
yesno
Where you have a business need to use unsupported software, have you moved the devices and software out of scope of this assessment?
yesnodescribe
Does your organisation meet the Security Update Management requirements?
Check your real-world posture across all 5 Cyber Essentials control areas in 3 minutes. Free, no account needed.