ISO/IEC 27001:2022 Annex A · Control 8.19
Installation of Software on Operational Systems: A Practical Implementation Guide
Permit only authorized, tested and supportable software on production and operational systems.
This control concerns securely managing software installation on operational systems.
What should the control achieve?
- Software installation authority is restricted.
- Packages come from trusted sources.
- Changes are tested and approved.
- Unauthorized and unsupported software is detected.
Step-by-step implementation
Define permitted software
Maintain catalogues, versions, support status and business owners.
Restrict installation
Remove local install rights and use controlled deployment tools.
Verify source and integrity
Use approved repositories, signatures, hashes and provenance.
Assess and test
Review security, compatibility, licensing and rollback in non-production.
Deploy through change
Record target, version, approval and outcome.
Monitor inventory
Detect unauthorized, obsolete and vulnerable software.
What this could look like in practice
Production servers accept packages only from an internal signed repository through automation. Emergency installations require expedited change approval and retrospective review.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Request | Owner justifies software and version. | Request |
| Package intake | Signature and source are verified. | Repository record |
| Deployment | Automation applies approved change. | Deployment log |
| Discovery | Inventory identifies unauthorized installation. | Finding ticket |
Implementation evidence
- Software-installation policy
- Approved catalogue
- Deployment permissions
- Package verification
- Test results
- Change records
- Software inventory
- Unauthorized-software findings
Useful metrics
- Unauthorized software
- Unsupported versions
- Installations outside deployment process
- Inventory coverage
Common mistakes
- Allowing administrators to install ad hoc tools.
- Downloading directly from search results.
- Ignoring scripts, browser extensions and agents.
- No rollback plan.
- Keeping trial or unused software.
Questions an auditor may ask
- Who may install software?
- How are packages trusted?
- Show an emergency installation.
- How is unauthorized software detected?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.