# Maintain software throughout its useful life

Taiga Learning · Worksheet
https://taiga.training/en/lessons/maintenance/

Use fictional or approved information. Do not put secrets in this worksheet.

## Learning objectives
- Separate routine maintenance from incident response.
- Prioritize work from exposure, exploitation, and service impact.
- Verify that a maintenance correction reaches the running service.

## Exercise
Use the four fictional findings in this lesson. Assign an owner, first action, verification method, and review time to each. Explain which new observation would change your priority.

## Your response
- Scenario and scope:
- Assumptions and open questions:
- Proposed answer or decision, with reasons:

## Verify your response
| Claim or criterion | Evidence or test | Result or gap | Owner |
| --- | --- | --- | --- |
| | | | |
| | | | |
| | | | |

## Next action
- Action, owner, and date:
- When will you review this response?

## Principle to retain
Maintenance is continuing engineering work. A merged fix does not prove that production runs the corrected version.

## Sources
- [NIST: Secure Software Development Framework](https://csrc.nist.gov/pubs/sp/800/218/final)
- [CISA: Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [Taiga docs: Maintaining](https://docs.tai.ga/operate/maintaining/)

This worksheet supports learning. Completing it does not itself authorize a production change.
