<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAP Security Notes - application cadence? in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-notes-application-cadence/m-p/12148645#M1976796</link>
    <description>&lt;P&gt;Our auditors have suggested that we need to increase the frequency of which SAP security notes are applied to our systems, i.e. Hot News/Severity 1 within 30 days, Highs/Severity 2 within 60 days, etc.&lt;/P&gt;
  &lt;P&gt;I can understand the desire/need but feel that might not be the right balance between keeping the systems secure and meeting the needs of the business through enhancements much more "tangible" to them, especially given tight IT resources.&lt;/P&gt;
  &lt;P&gt;Best practice aside, I'm interested in knowing more about what others are actually doing in this regard. How often are others applying security notes depending on their severity? &lt;/P&gt;</description>
    <pubDate>Mon, 27 Apr 2020 19:30:09 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2020-04-27T19:30:09Z</dc:date>
    <item>
      <title>SAP Security Notes - application cadence?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-notes-application-cadence/m-p/12148645#M1976796</link>
      <description>&lt;P&gt;Our auditors have suggested that we need to increase the frequency of which SAP security notes are applied to our systems, i.e. Hot News/Severity 1 within 30 days, Highs/Severity 2 within 60 days, etc.&lt;/P&gt;
  &lt;P&gt;I can understand the desire/need but feel that might not be the right balance between keeping the systems secure and meeting the needs of the business through enhancements much more "tangible" to them, especially given tight IT resources.&lt;/P&gt;
  &lt;P&gt;Best practice aside, I'm interested in knowing more about what others are actually doing in this regard. How often are others applying security notes depending on their severity? &lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 19:30:09 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-notes-application-cadence/m-p/12148645#M1976796</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2020-04-27T19:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: SAP Security Notes - application cadence?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-notes-application-cadence/m-p/12148646#M1976797</link>
      <description>&lt;P&gt;CVSS score is a good place to start. Anything from 6.9 or higher I would implement immediately. All others could be fitted around the usual patching. &lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 21:33:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sap-security-notes-application-cadence/m-p/12148646#M1976797</guid>
      <dc:creator>former_member612251</dc:creator>
      <dc:date>2020-04-27T21:33:46Z</dc:date>
    </item>
  </channel>
</rss>

