SAMMY UI is optimized for resolutions with a width 1024px and higher.
Maturity Level 1
Maturity Level 2
Maturity Level 3
Maintain operational environment specification
814: Do projects document operational environment security requirements?
  • The organization documents and maintains a set of baseline operating platforms.
  • project teams expand on existing, approved baseline operating platforms to meet project requirements.
  • Project teams document assumptions made about operating environments during development.
  • Organization and project operating platforms are reviewed at least every six months.
Description

For each project, a concrete definition of the expected operating platforms should be created and maintained. Depending on the organization, this specification should be jointly created with development staff, stakeholders, support and operations groups, etc. Begin this specification should by capturing all details that must be true about the operating environment based upon the business function of the software. These can include factors such as processor architecture, operating system versions, prerequisite software, conflicting software, etc. Further, note any known user or operator configurable options about the operating environment that affect the way in which the software will behave. Additionally, identify any relevant assumptions about the operating environment that were made in design and implementation of the project and capture those assumptions in the specification. This specification should be reviewed and updated at least every six months for active projects or more often if changes are being made to the software design or the expected operating environment.

Maintain operational environment specification
814: Do projects check for security updates to third-party software components?
  • Project teams or the operations team regularly monitors software components for security updates.
  • Project teams or the operations team apply critical software component updates once identified.
Description

For each project, a concrete definition of the expected operating platforms should be created and maintained. Depending on the organization, this specification should be jointly created with development staff, stakeholders, support and operations groups, etc. Begin this specification should by capturing all details that must be true about the operating environment based upon the business function of the software. These can include factors such as processor architecture, operating system versions, prerequisite software, conflicting software, etc. Further, note any known user or operator configurable options about the operating environment that affect the way in which the software will behave. Additionally, identify any relevant assumptions about the operating environment that were made in design and implementation of the project and capture those assumptions in the specification. This specification should be reviewed and updated at least every six months for active projects or more often if changes are being made to the software design or the expected operating environment.