If software that is not standards-compliant is installed in that same environment, then every application will be considered as non-compliant anymore.I know that existing security standards such as PCI and OWASP do require that all security patches be installed on the system, and if potential security holes with third-party software are found during the audit that a bug report is filed; however, I