Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.19

Installation of Software on Operational Systems: A Practical Implementation Guide

Permit only authorized, tested and supportable software on production and operational systems.

This control concerns securely managing software installation on operational systems.

Practical interpretation: Installation changes attack surface, stability, licensing and support. It should follow ownership, approval, trusted source, testing and rollback processes.

What should the control achieve?

  • Software installation authority is restricted.
  • Packages come from trusted sources.
  • Changes are tested and approved.
  • Unauthorized and unsupported software is detected.

Step-by-step implementation

1

Define permitted software

Maintain catalogues, versions, support status and business owners.

2

Restrict installation

Remove local install rights and use controlled deployment tools.

3

Verify source and integrity

Use approved repositories, signatures, hashes and provenance.

4

Assess and test

Review security, compatibility, licensing and rollback in non-production.

5

Deploy through change

Record target, version, approval and outcome.

6

Monitor inventory

Detect unauthorized, obsolete and vulnerable software.

What this could look like in practice

Production servers accept packages only from an internal signed repository through automation. Emergency installations require expedited change approval and retrospective review.

ActivityPractical implementationEvidence
RequestOwner justifies software and version.Request
Package intakeSignature and source are verified.Repository record
DeploymentAutomation applies approved change.Deployment log
DiscoveryInventory identifies unauthorized installation.Finding ticket

Implementation evidence

  • Software-installation policy
  • Approved catalogue
  • Deployment permissions
  • Package verification
  • Test results
  • Change records
  • Software inventory
  • Unauthorized-software findings

Useful metrics

  • Unauthorized software
  • Unsupported versions
  • Installations outside deployment process
  • Inventory coverage

Common mistakes

  • Allowing administrators to install ad hoc tools.
  • Downloading directly from search results.
  • Ignoring scripts, browser extensions and agents.
  • No rollback plan.
  • Keeping trial or unused software.

Questions an auditor may ask

  • Who may install software?
  • How are packages trusted?
  • Show an emergency installation.
  • How is unauthorized software detected?
Implementation test: Trace one production package from request and provenance through testing, deployment, inventory and later update.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.