EXPERIENCES AND LESSONS LEARNED FROM A SIEMENS-WIDE SECURITY PATCH MANAGEMENT SERVICE FOR PRODUCTS

No ratings

Presented at First 2017 by

In software development, using third-party open-source as well as proprietary software components has become the de-facto standard. These pre-made building blocks enable faster time to market and lower development costs by providing out-of-the box functionality, allowing developers to focus on product-specific customizations and features. However, decision makers and developers must be aware that they possibly inherit the security issues of components they incorporate and that they have to care. Based on experiences from a Siemens-wide self-operated, self-developed security patch management service for products in the critical infrastructure space, the presentation will discuss lessons learned and give insights into pitfalls and how to tackle them.