Patching
Organizations can automate their patching strategy for mutable compute environments and keep mutable instances in-line with the defined patch baseline of that application environment by using AWS Systems Manager Patch Manager and AWS Lambda. A tagging strategy for mutable instances within these environments can be managed by assigning said instances to Patch Groups and Maintenance Windows. See the following examples for a Dev → Test → Prod split. AWS prescriptive guidance is available for the patch management of mutable instances.
Table 10 - Operational tags can be environment specific
Development | Staging | Production |
---|---|---|
|
|
|
Zero-day vulnerabilities can also be managed by having tags defined to complement your
patching strategy. Refer to Avoid zero-day vulnerabilities with same-day security patching using AWS Systems Manager