From the course: CSSLP Cert Prep: 6 Secure Lifecycle Management

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Ongoing configuration management

Ongoing configuration management

From the course: CSSLP Cert Prep: 6 Secure Lifecycle Management

Start my 1-month free trial

Ongoing configuration management

- [Narrator] Once you've defined secure configuration and version management controls for hardware and software, you should turn your attention toward maintaining those secure configurations over time. Three things you can use to accomplish this are documentation, interfaces, and software security patches. A certain configuration items are set during installation and deployment. While other configuration items are accessible through different application interfaces, user interfaces should ideally limit configuration items to individual users. A user may be able to change their own password for example but it's unlikely they'll need the ability to change someone else's password. Admin interfaces have access to security configuration items that can affect the entire app, as well as all users who can access the app. Admins may be able to update TLS certificates, change user passwords, and configure connections to other…

Contents