Security Advisories new
OSC identifies, assesses, and responds to security vulnerabilities by using multiple trusted advisory sources and applying risk-based patching and mitigation measures.
Sources of Vulnerability Information
To identify and evaluate vulnerabilities and threats that may affect OSC services, as early as possible, the OSC Security Team receives reports from the following sources:
- T-Systems dedicated Computer Emergency Response Team (dCERT)
- Intel® Product Security Center Advisories
- Dell Security Advisories
- Lenovo Product Security Advisories and Announcements
- NIST
- Gardener
- SCONE Security Bulletin
Patching of Vulnerabilities
After the evaluation of vulnerabilities, their severity and level of risk will determine what enforcement action will be taken. E.g.:
- regular release deployment
- extraordinary patch deployment
- deployment of special settings for risk mitigation