ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.19: Installation of software on operational systems

Procedures and measures are to be put in place so that installing software on operational systems is managed securely. Purpose: keep operational systems intact and prevent technical vulnerabilities being exploited. Guidance: consider having operational software updated only by trained administrators with management authorization; installing only approved executable code, never development code or compilers, on operational systems; installing or updating software only after extensive, successful testing (8.29, 8.31); updating all related program source libraries; controlling all operational software and system documentation through a configuration control system; deciding how to roll back before any change goes in; keeping an audit log of every update to operational software; and archiving previous versions together with everything needed to run them again, such as parameters, procedures, settings and supporting software, as a contingency and for as long as they are needed to read or process archived data. Decisions to move to a new release weigh the business need and the release's security, such as new security features or the number and severity of vulnerabilities in the current version, and patches are applied where they remove or reduce vulnerabilities (8.8). Software that depends on externally hosted modules or packages should be monitored and controlled against unauthorized changes that could introduce vulnerabilities. Vendor software should be kept at a supported level and open source software at the latest suitable release, with the risks of unsupported or no longer maintained software considered. Suppliers installing or updating software get physical or logical access only when necessary and authorized, and their activity is monitored (5.22). Strict rules define which software users may install, applying least privilege: identify permitted installations such as updates or security fixes for software already in use and prohibited ones such as software for personal use or of unknown or suspect origin, and grant installation rights by role.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 87 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 11 controls

CIS Controls v8 · 7 controls

  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.3 Address Unauthorized Software
  • CIS-2.5 Allowlist Authorized Software
  • CIS-2.6 Allowlist Authorized Libraries
  • CIS-2.7 Allowlist Authorized Scripts
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions

FedRAMP High · 7 controls

  • CM-10 Software Usage Restrictions
  • CM-11 User-Installed Software
  • CM-5 Access Restrictions for Change
  • CM-7(2) Prevent Program Execution
  • CM-7(5) Authorized Software Allow-by-Exception
  • CM-8(3) Automated Unauthorized Component Detection
  • SC-18 Mobile Code

FedRAMP Moderate · 7 controls

  • CM-10 Software Usage Restrictions
  • CM-11 User-Installed Software
  • CM-5 Access Restrictions for Change
  • CM-7(2) Prevent Program Execution
  • CM-7(5) Authorized Software Allow-by-Exception
  • CM-8(3) Automated Unauthorized Component Detection
  • SC-18 Mobile Code
  • ISM-0843 Application control on workstations
  • ISM-1235 Restricting add-ons, extensions and plug-ins
  • ISM-1592 Blocking user installation of unapproved applications
  • ISM-1657 Application control scope of file types

HIPAA Security Rule · 4 controls

NIST SP 800-161 Rev 1 · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

PCI DSS 4.0 · 4 controls

  • 5.3.5 5.3.5 Users cannot disable or alter anti-malware
  • 6.4.3 6.4.3 Payment page script management
  • 6.5.1 6.5.1 Change control procedure for production
  • 8.6.2 8.6.2 No hard-coded passwords for interactive system accounts
  • AM-2 Use only approved services
  • ASBv3-AM-5 Use only approved applications in virtual machine
  • ASBv3-PV-4 Audit and enforce secure configurations for compute resources

CMMC 2.0 · 3 controls

ACSC Essential Eight · 2 controls

  • E8-APP-ML1 Application Control (ML1)
  • E8-APP-ML2 Application Control (ML2)

C5 (Germany) · 2 controls

  • C5-DEV-09 Approvals for provision in the production environment
  • C5-PSS-11 Images for Virtual Machines and Containers

NIST SP 800-171 Rev 3 · 2 controls

  • 03.04.05 Access Restrictions for Change
  • 03.04.08 Authorized Software - Allow by Exception

NIST SP 800-172 · 2 controls

  • 3.4.1e Authoritative Source for Software and Firmware
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

SOC 2 · 2 controls

  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

UK Cyber Essentials · 2 controls

  • CE-MP.4 Application Allowlisting (Alternative)
  • CE-SC.1 Remove or Disable Unused Software
  • ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need
  • ASD37-01 Application control (Essential)
  • AUCDR-IS-5 Limit, prevent, detect and remove malware

ISO 27001:2022 · 1 control

  • 8.19 Installation of software on operational systems

MTCS (Singapore) · 1 control

  • 14.9 Unauthorised software

NIS2 Directive · 1 control

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-218 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.19 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 87 it maps to, and the evidence behind each claim, over MCP and REST.