Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Include Page
InCFederation:Draft Notice
InCFederation:Draft Notice
Tip
titleBest Practice
  • Appropriate staff monitor "security" and/or "announce" mailing lists for critical software.
  • Software versions are reasonably current and upgraded ahead of "End of Life" dates.

Federation software relies on an extensive technology stack. As with all web-based software, vulnerabilities can be introduced in many places, and a security flaw on one site can lead to the exposure of another. This is particularly true when web authentication software is involved.

...

Avoid big-bang upgrades crossing multiple significant versions. Ensure staff are monitoring the appropriate mailing lists to stay abreast of security issues and patches. In general, treat your environment the way you would treat any mission-critical system.

...

titleBest Practice

...

.