2.2: Ensure Authorized Software is Currently Supported

CSF v1.1 References:

Group:

Previous Version:

Control Statement

Ensure that only currently supported software is designated as authorized in the software inventory for enterprise assets. If software is unsupported, yet necessary for the fulfillment of the enterprise’s mission, document an exception detailing mitigating controls and residual risk acceptance. For any unsupported software without an exception documentation, designate as unauthorized. Review the software list to verify software support at least monthly, or more frequently.

[csf.tools Note: For more information on the Critical Security Controls, visit the Center for Internet Security.]