U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

NIST SP 800-40 Version 2

Creating a Patch and Vulnerability Management Program

Date Published: November 2005

Supersedes: SP 800-40 (08/01/2002)

Author(s)

Peter Mell (NIST), Tiffany Bergeron (MITRE), David Henning (Hughes Network Systems)

Abstract

Keywords

computer security; security patches; vulnerability management
Control Families

Awareness and Training; Configuration Management; Planning; Risk Assessment

Documentation

Publication:
https://doi.org/10.6028/NIST.SP.800-40ver2
Download URL

Supplemental Material:
None available

Document History:
11/16/05: SP 800-40 Version 2 (Final)

Topics

Security and Privacy

patch management, vulnerability management

Applications

enterprise