Installation of software on operational systems
Purpose
Manage how software is installed on live operational systems so integrity stays intact and vulnerabilities are not introduced.
How to meet this control
In short: Manage secure installation of software on operational systems.
- Step 01Restrict installation rights on production systems to trained, authorised administrators and remove local admin from general users
- Step 02Install only approved, signed software from controlled repositories or app catalogues and keep compilers and development tools off production
- Step 03Test every installation or update in a staging environment and require change approval before promoting to production
- Step 04Maintain a configuration and version record of operational software, and archive previous versions and their settings for rollback
- Step 05Define a documented rollback plan before any change goes in and keep an audit log of updates
- Step 06Apply application control or allowlisting so unapproved executables cannot run on operational hosts
Tip: Restrict who can install; use approved repositories/app catalogues.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Only let trained administrators update operational software, with management approval
- ›Install only approved executable code, keeping development code and compilers off production
- ›Carry out thorough, successful testing before installing or updating any software
- ›Use a configuration control system to track operational software and documentation
- ›Define a rollback plan before any change goes in and keep an audit log of updates
- ›Archive old software versions plus their settings and supporting files as a fallback
- ›Apply security patches promptly, weighing business need and release risk
- ›Apply least privilege and enforce clear rules on what software users may install
Audit evidence to keep
- - Policy restricting who may install software on production systems
- - Approved software catalogue or repository configuration
- - Change records showing testing and approval before deployment
- - Rollback plan and version archive for a recent change
- - Application allowlisting configuration on operational hosts
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.8.19. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.