Security Notification and Update Management

Security Notification tailored to your software platform + Easy Patch/upgrade = Peace of mind

With the increasing rate of information-security vulnerabilities and the unpredictability of discoveries, the manual process of keeping up the newly discovered vulnerabilities for your device software is not feasible. Timesys helps reduce the time and costs associated with maintaining software security through its automated Security Notification and Update Management Service.

At core is Timesys’ Threats Response Security Team (TRST) — a team of embedded Linux engineers that constantly monitors security issues that impact open source software being used by Timesys customers and updates the Timesys CVE manager and Repositories.

How Timesys’ Security Notification Works

Timesys utilizes a Timesys-built Common Vulnerabilities and Exposures (CVE) manager

Discover and Identify

The Timesys Security Team utilizes a Timesys-built Common Vulnerabilities and Exposures (CVE) manager to gather/pull information from nvd.nist.gov and security mailing lists and identify security issues relevant to the code in the Timesys source code repository.

Timesys analyzes the state of the vulnerability

Analyze

The Timesys Security Team then analyzes the state of the vulnerability (known vulnerability with available patch or update vs. known vulnerability with no fix available).

the Timesys security team adds security updates and patches to the code in the Timesys source code repository

Update and Patch

The Timesys Security Team adds available security updates and patches to the code in the Timesys source code repository.

Timesys customers have access to pull notifications for discovered security vulnerabilities unique to their build

Notify

To determine if any security issues are known to affect their device / build, customers using Timesys’ Yocto Project Café or Factory desktop development environment can pull notification by running a check CVE command.

All customers can optionally store their workorder or manifest in Timesys’ web development environment and get push notification.

Timesys’ Automated BSP Security Monitoring and Update Management Service

Eliminate the Time Spent Monitoring CVEs Yourself

With Timesys’ Security Notification, tracking relevant security vulnerabilities for your build is easy. You have access to on-demand notification that enables you to request a list of fixed CVEs as well as potentially unresolved security issues that are relevant for only the software components used in your particular configuration.

Integrate Updates and Patches
with Confidence

With the Timesys Security Update service, it’s easy to apply updates and security patches into your software, and you remain in control of what gets updated.
 

<div align="center"><h2>Want to learn more about Timesys’ automated Security Notification and Update Management capabilities?</h2><p>We’d be happy to answer your questions and provide you with more information about how Timesys solutions can make your developments more secure and up-to-date while helping reduce development and lifecycle costs and time. To contact us, simply fill out our online form, email us at <a href="mailto:sales@timesys.com?subject=I'd like information about Timesys security offering"><strong>sales@timesys.com</strong></a> or call us at <strong>1.866.392.4897</strong> (toll-free) or <strong>+1.412.232.3250</strong>.</p><p><a class="et_pb_promo_button et_pb_button darker" href="/request-contact" style="letter-spacing: normal;">Contact Us</a></p></div>