Controls / Patching
Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed
What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: replace or remove software and devices the vendor no longer supports.
In Australia
Maturity Level One
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| ISM-1501 Essential Eight, Maturity Level One | Operating systems that are no longer supported by vendors are replaced. Required at Maturity Levels One, Two and Three of the Patch operating systems mitigation strategy (Appendices A, B and C); ISM control ISM-1501 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Operating system version inventory (for example winver output or scanner OS fingerprinting) compared with vendor support lists; Replacement or upgrade records for operating systems that reached end of support |
| ISM-1704 Essential Eight, Maturity Level One | Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1704 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Software inventory of office suites, browsers and extensions, email clients, PDF software and security products checked against vendor support lifecycles; Evidence that the retired browser plug-in named in the requirement is removed (the removal hotfix or an equivalent record) |
| ISM-1905 Essential Eight, Maturity Level One | Online services that are no longer supported by vendors are removed. Required at Maturity Levels One, Two and Three of the Patch applications mitigation strategy (Appendices A, B and C); ISM control ISM-1905 in ASD's Essential Eight to ISM mapping (December 2023). evidence an assessor asks for Inventory of online services in use with vendor support status and end-of-support dates; Decommissioning records for online services that reached end of support |
In the United States
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 2.2 CIS Controls v8.1 | Ensure Authorized Software is Currently Supported Only software that still receives vendor support may be marked as authorised in the enterprise software register. Where unsupported software is still needed for the mission, record an exception that sets out the compensating controls and the acceptance of remaining risk. Unsupported software with no recorded exception is to be marked unauthorised. Check the list for support status no less often than monthly. evidence an assessor asks for Authorised software list compared with vendor support status, showing only supported software authorised; Exception register for unsupported software with mitigating controls and residual risk acceptance; Monthly support status check record comparing each authorised title with vendor end-of-life announcements; Software register entries for end-of-support titles marked unauthorised where no exception exists; Risk acceptance sign-offs by a named business owner for each unsupported title kept for the mission |
| PR.PS-02 NIST CSF 2.0 | Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect. evidence an assessor asks for Software lifecycle policy with end of support tracking; Patch management cadence and exception register; End of life replacement plan; Software risk assessments for unsupported tools; Software retirement records |
In United Kingdom
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SU.1 Cyber Essentials | Software Licensed and Supported All software on in-scope devices must be licensed and supported by the vendor (i.e. receiving security updates). Unsupported software must be removed or segregated. evidence an assessor asks for Software inventory from the device management tool; EOL/EOSL register; segregation evidence for unsupported |
| CE-SU.4 Cyber Essentials | Remove Out-of-Support Software Remove software that is no longer receiving security updates from in-scope devices, or fully segregate it from the rest of the network. evidence an assessor asks for EOL removal log; segregated VLAN evidence; compensating control documentation |
Also cited: ISO/IEC 27001:2022 Annex A
A lens in any jurisdiction, never a gap on its own.
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| A.8.8 ISO/IEC 27001:2022 (lens) | Management of technical vulnerabilities The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8. evidence an assessor asks for Statement of Applicability entry for control A.8.8, showing inclusion or justified exclusion, implementation status and the risks it treats; A software asset inventory with vendor, product, version, deployment location and responsible owner; Defined vulnerability management roles and a list of monitored vulnerability information sources; Authenticated scan results and penetration test reports by authorized testers, with verification scans after patching; Remediation timelines by severity with measured performance, and risk records weighing the vulnerability against update risk |
Questions
- What does the applicant report for this control?
- Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
- When is it due on the 90-day schedule?
- Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
- Does this page check the control?
- No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.