Consider adding needrestart to our monitoring
Needrestart:
- Detects running processes that are using outdated libraries.
- Is able to either only list or automatically restart (some) processes.
- Is complementary to "reboot-required" in a sense.
Note: For S11, this fits in:
-
B.2 - Keep our infrastructure up-to-date and secure
: Having visibility of services that need to restarted because of outdated libraries decreases the chances of malicious actors benefiting from known vulnerabilities that have already been fixed and deployed but have not yet been made effective because of lack of manual intervention.
Edited by groente-admin