ISO27001:2022 – A8.19

Installation of software on operational systems

Want to fast track your ISO 27001 journey? 

Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).

Introduction to ISO 27001 – A8.19

Remembering that at  the heart of information security are the principles of Confidentiality, Integrity and Availability, it should come as no surprise that ISO27001 requires us to control the installation of software on operating systems. 

The purpose of ISO 27001 – A8.19 is to ensure not only the integrity of operational systems and prevent exploitation of technical vulnerabilities, but also to ensure that you have control of what systems have been installed.  Don’t do this, and the result will be ‘Shadow IT’ in your business – uncontrolled and unsupported.

But as with many aspects of ISO27001, the control is deceptively simple but critically important. 

What does ISO 27001 – A8.19 require?

The standard states that “Procedures and measures shall be implemented to securely manage software installation on operational systems.” (A8.19 – Installation of software on operational systems) 

Note the use of the phrase, ‘procedures and measures’ indicating that there will be a mix of procedures (to follow), and either operational or technical measures to manage software installation. We will look at this in more details shortly. 

Why is this required?

If you don’t have controls in place to manage the installation of software on operational systems then you run the risk of people installing software which is uncontrolled, and unlicenced.

 In technical terms, this is often referred to as ‘shadow IT’ systems, meaning applications which are not managed, supported or controlled by the IT function.  It should come as no surprise what the impact of this could be, as uncontrolled software could breach licence agreements, or perform actions which negatively impact upon your systems or infrastructure.

Without technical controls in place, there is a risk that if users have the ability to install software, they could also install malicious software (Malware) that causes severe damage both financially and reputationally.

There could be a risk of system disruption as uncontrolled installation interrupts legitimate systems and services. This could be a sudden incident, or a slow degrading of the system, which could go unnoticed for some time, leading to significant, long terms issues.

What the auditor is looking for

For this ISO27001 control, the auditor will expect to see a variety of security measures that might include;

What do you need to do?

You should first speak to your IT team to understand if and how the installation of software is controlled on your devices and network. In smaller businesses, it is not uncommon to find this control has not been uniformly applied, and some users are given ‘Admin’ access to their systems almost by default.  If this is the case, then you will need to revisit your access control policy, which you defined as part of ISO27001 Annex A control, A5.15 (Access Control) and A5.18 (Access Rights) and apply compensating controls (such as procedures).

It’s important to ensure that installation of software is only carried out by suitably qualified individuals, typically those responsible for IT.

You should also review ISO27001 Annex A control A8.18 (Use of privileged utility programs), to ensure that users are not installing privileged utility programs.

Review your change management processes so that you are sure that installation of software is only permitted by authorised individuals, and after testing has been completed.

Difficulty rating

We rate this a 1.5 out of 5 difficulty rating. This control requires further consultation with your IT function, to understand how installation of software takes place.  Where you are not able to control the installation of software, you should identify and assess the risk and ensure this is managed through your risk management process.

Q&A

Do I need a policy?

No, you don’t need a topic-specific policy, but you might look to include reference to the installation of software in your acceptable use policy.

More questions?

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” which is available on Amazon.

Fastback your journey to ISO27001 and buy our Policies to get started TODAY!

Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!

ISO 27001 – A8.19 – Installation of software on operational systems