ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityMedium
During the maintenance phase of a critical business application, a zero-day vulnerability is discovered in a core library. The vendor releases an emergency patch. What is the most critical security consideration for the operations team when applying this patch?
- APerforming a full system backup before applying the patch.
- BVerifying the authenticity and integrity of the patch before deployment.
- CDocumenting the patch application process for future reference.
- DEnsuring the patch is applied during off-peak hours to minimize user impact.
Show answer & explanationAnswer & explanation
Correct answer: B. Verifying the authenticity and integrity of the patch before deployment.
In the case of a zero-day vulnerability and an emergency patch, verifying the authenticity (that it's from the legitimate vendor) and integrity (that it hasn't been tampered with) of the patch is paramount. Applying a malicious or compromised patch could introduce new, severe vulnerabilities or backdoors, potentially worsening the security posture.
Why the other options are wrong
- A. A full system backup is a wise operational precaution for recovery, but it does not address the security risk of deploying a potentially malicious patch.
- C. Documentation is good practice but secondary to ensuring the patch itself is safe and legitimate.
- D. Minimizing user impact is an operational concern, but not the most critical *security* consideration regarding the patch itself.
Patch Authenticity & Integrity
The process of verifying that a software patch originates from a legitimate source and has not been altered or corrupted since its release.
- Prevents supply chain attacks
- Often uses digital signatures (authenticity)
- Checksums/hashes verify integrity
Memory trick: Patch 'em up quick, but verify first, or a new vulnerability might burst!