Direct Application of Patches for SaaS and Cloud Offerings, v1.0

Specifies requirements in accordance with the DHS CISA Secure-by-Design Pledge, published by the U.S. Dept of Homeland Security (DHS) Cybersecurity and Infrastructure Agency (CISA). Requires an organization to apply patches directly for all of its cloud-based and Software-as-a-Service (SaaS) product and service offerings without requiring customer action.

Assessment Step

1
Direct Application of Patches for SaaS and Cloud Offerings (DirectApplicationofPatchesforSaaSandCloudOfferings)
Does the organization apply patches directly for all of its cloud-based and Software-as-a-Service (SaaS) product and service offerings without requiring customer action?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Direct Application of Patches for SaaS and Cloud Offerings
The organization must apply patches directly for all of its cloud-based and Software-as-a-Service (SaaS) product and service offerings without requiring customer action.
Citation
SBDP
(doc)