Log4Shell Update and Resources

Security
Author: Scott Reynolds, Senior Director, Enterprise Cybersecurity
Date Published: 23 December 2021

ISACA Community,

In the past week, you’ve likely seen multiple headlines about a new major security vulnerability. Log4j is an open-source logging framework built on Java coding language that is used by approximately one-third of all webservers. On 9 December, a flaw in the code was discovered and rated a 10 out of 10 on the Common Vulnerability Scoring System (CVSS) due to its possible impact. 

We have confirmed that the ISACA platform is NOT affected by the Log4Shell vulnerability or any of its components.

However, because this is a very commonly used java-based software that attackers can use to gain a foothold via vendor software or services, we have been checking the status of our vendors’ patching activity and will continue tracking this issue until it has been remediated.

Below are three resources you might find helpful in learning more about this vulnerability:

Scott Reynolds
Senior Director, Enterprise Cybersecurity