Determine software vulnerabilities scan frequency
There is no specific time frequency that can be used to determine security scanning schedule.
Many of the vulnerabilities are disclosed on specific schedule, but not all of them.
There is no a specific magic wand to determine security scanning schedule.
It is needed to scan systems, when you suspect that released security patch will impact your systems, please be aware that security patches may be delayed by few days from security announcement, therefore security scan which is performed right after announcement of a security vulnerability may provide with a false sense of safety.
It is good however to perform security scans on regular basis, such as once a month. Results of such scans will show what is needed to be fixed and priority of such fixes.
Not all of the vulnerabilities exist of the bad operating system code, or installed applications, some vulnerabilities exist because of incorrect configuration, or insecure development practices.
Comments
Post a Comment