2.2: Ensure Authorized Software is Currently Supported
CSF v1.1 References:
Previous Version:
- Critical Security Controls Version 7.1:
- 2.2: Ensure Software is Supported by Vendor
Control Statement
Ensure that only currently supported software is designated as authorized in the software inventory for enterprise assets. If software is unsupported, yet necessary for the fulfillment of the enterprise’s mission, document an exception detailing mitigating controls and residual risk acceptance. For any unsupported software without an exception documentation, designate as unauthorized. Review the software list to verify software support at least monthly, or more frequently.
[csf.tools Note: For more information on the Critical Security Controls, visit the Center for Internet Security.]