There are several excellent resources emerging in the face of this vulnerability:
- CISA has published an Apache Log4j Vulnerability Guidance page: https://www.cisa.gov/uscert/apache-log4j-vulnerability-guidance
- Log4j Security Vulnerabilities page: https://logging.apache.org/log4j/2.x/security.html
- CISAβs Cyber Essentials: https://www.cisa.gov/cyber-essentials
ControlCase Policy and Procedure Templates which may protect against future attacks:
- Business Continuity Plan Policy and Procedures Template: https://dev.controlcase.com/business-continuity-policy-template/
- Incident Management Policy Template: https://dev.controlcase.com/incident-management/
- IT Security Policy Template: https://dev.controlcase.com/it-security-policy-template/
- Vulnerability Management Template: https://dev.controlcase.com/vulnerability-management-templates/
