CIS Controls v8
CIS Control 2: Inventory and Control of Software Assets

CIS Controls v8 CIS-2.2: Ensure Authorized Software is Currently Supported

Only software that still receives vendor support may be marked as authorised in the enterprise software register. Where unsupported software is still needed for the mission, record an exception that sets out the compensating controls and the acceptance of remaining risk. Unsupported software with no recorded exception is to be marked unauthorised. Check the list for support status no less often than monthly.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 63 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 7 controls

ISO 27002:2022 · 5 controls

  • 5.36 Compliance with policies, rules and standards for information security
  • 5.9 Inventory of information and other associated assets
  • 8.19 Installation of software on operational systems
  • 8.32 Change management
  • 8.8 Management of technical vulnerabilities
  • NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk

PCI DSS 4.0 · 5 controls

  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 5.2.1 5.2.1 Anti-malware deployed on all system components
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.2 6.3.2 Inventory of bespoke software and components
  • 6.3.3 6.3.3 Timely installation of security patches

SOC 2 · 5 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

HIPAA Security Rule · 4 controls

ISO 27001:2022 · 4 controls

  • 5.9 Inventory of information and other associated assets
  • 8.19 Installation of software on operational systems
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

NIST SP 800-66 Rev 2 · 4 controls

  • ISM-0304 Removing unsupported applications
  • ISM-1501 Replacing unsupported operating systems
  • ISM-1809 Compensating controls for unsupported systems
  • ASD37-02 Patch applications (Essential)
  • ASD37-19 Patch operating systems (Essential)

FedRAMP High · 2 controls

  • CM-10 Software Usage Restrictions
  • SA-22 Unsupported System Components (SA-22)

FedRAMP Moderate · 2 controls

  • CM-10 Software Usage Restrictions
  • SA-22 Unsupported System Components (SA-22)

UK Cyber Essentials · 2 controls

  • CE-SU.1 Software Licensed and Supported
  • CE-SU.4 Remove Out-of-Support Software
  • E8-PATCHAPP-ML3 Patch Applications (ML3)
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems

APRA CPS 234 · 1 control

  • CPS234-P17 Active Maintenance of Capability Against Change
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities

C5 (Germany) · 1 control

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept

CIS Controls v8.1 · 1 control

  • 2.2 Ensure Authorized Software is Currently Supported

DORA · 1 control

NIST SP 800-172 · 1 control

  • 3.4.1e Authoritative Source for Software and Firmware

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 2: Inventory and Control of Software Assets

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-2.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 63 it maps to, and the evidence behind each claim, over MCP and REST.