SI-2(6): Removal of Previous Versions of Software and Firmware

Parent Control:

SI-2: Flaw Remediation

CSF v1.1 References:

Baselines:

(Not part of any baseline)

Previous Version:

Control Statement

Remove previous versions of [Assignment: organization-defined software and firmware components] after updated versions have been installed.

Supplemental Guidance

Previous versions of software or firmware components that are not removed from the system after updates have been installed may be exploited by adversaries. Some products may automatically remove previous versions of software and firmware from the system.