Orphaned Software and Systems Security Assessment

Organizations sometimes are stuck with system elements that are no longer supported by their original manufacturer or vendor, and for which no effective thirdparty software or firmware support is available.

2 slides · 1 min read · Domain 8

Slide 1

Both 2019 and 2020 saw multiple reports

It is worth noting the distinction between from the United Kingdom in which doctors' a legacy system and an orphaned one. The offices had to remain operating on Windows legacy system is still being supported, XP-based systems primarily because the either by the in-house developers or a costs to replace orphaned, XP-dependent third party, and thus may (within reason) office and clinical devices was outside the be open to remediation of discovered vulnerabilities. Technological orphans reach of the budget. are generally unsupportable-at some Even without the source code, maintenance, point, they will have to be replaced, or be or design documentation, security abandoned along with the functions they assessment can still be worthwhile.

had been performing for the organization.

Common Vulnerabilities and Exposures

Ultimately, refactoring of the entire

(CVE) data will reveal potential business process that is currently using the vulnerabilities in a specific situation that orphaned technology may be the best bet.

a security professional may not be able to fix, but it might be possible to mitigate in other ways.

Test this domain