{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Framework: The NIST Cybersecurity Framework (CSF)","title":"PR.PS-02 - Maintaining Software Security","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/6bd09326\"></iframe>","width":"100%","height":180,"duration":991,"description":"PR.PS-02 focuses on maintaining, replacing, or removing software based on risk, including timely patching, updating container images, and phasing out end-of-life versions. This ensures software remains supported and secure, reducing vulnerabilities from outdated or unauthorized applications. It includes plans for obsolescence to manage lifecycle risks.\nThis subcategory strengthens resilience by uninstalling unnecessary or risky software components that could be exploited, aligning updates with vulnerability management timelines. It balances security with operational needs, ensuring only current, necessary software persists. PR.PS-02 keeps the software environment lean and protected.","thumbnail_url":"https://img.transistorcdn.com/ZQAUShkq6bmReWtsoCApAiEqnASSjulPAjN3RZCtsFI/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84YTE2/ZTU4ZDc5YjBhMjRj/MDkxMTllN2RmZDU5/YmU2My5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}