logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo logo

Deployment: Configuration Management and Vulnerability Management (CMVM)

The overall goal of the Configuration Management and Vulnerability Management practice is change management. The SSG and application owners must ensure their ability to track authorized changes to applications and to detect unauthorized changes and activity. Application owners must enforce adherence to corporate policy.

DEPLOYMENT: CONFIGURATION MANAGEMENT AND VULNERABILITY MANAGEMENT
Patching and updating applications, version control, defect tracking and remediation, incident handling.
  Objective Activity Level
CMVM1.1 know what to do when something bad happens create/interface with incident response 1
CMVM1.2 use ops data to change dev behavior identify software bugs found in ops monitoring and feed back to dev
CMVM2.1 be able to fix apps when they are under direct attack have emergency codebase response 2
CMVM2.2 use ops data to change dev behavior track software bugs found during ops through the fix process
CMVM2.3 know where the code is develop operations inventory of apps
CMVM3.1 learn from operational experience fix all occurrences of software bugs from ops in the codebase (T: code review) 3
CMVM3.2 use ops data to change dev behavior enhance dev processes (SSDL) to prevent cause of software bugs found in ops
one

CMVM Level 1: Use operations monitoring data to drive developer behavior. The SSG supports incident response. The SSG uses operations data to suggest changes in the SSDL and developer behavior.

two

CMVM Level 2: Ensure that emergency response is available during application attack. Managers and the SSG support emergency response to ongoing application attacks. Managers and the SSG maintain a code inventory. The SSG uses operations data to direct evolution in the SSDL and in developer behavior.

three

CMVM Level 3: Create a tight loop between operations and development. The SSG must ensure the SSDL both addresses code deficiencies found in operations and includes enhancements that eliminate associated root causes.