The ultimate audit guide to ISO 27001 Annex A 8.19 Installation of Software on Operational Systems
Table of contents
- 1. Software Installation Policy Formalisation Verified
- 2. Least Privilege and Administrative Right Restriction Confirmed
- 3. Use of Managed Deployment Tools Validated
- 4. Installation Integrity and Digital Signature Verification Confirmed
- 5. Operational Change Management Linkage Verified
- 6. Rollback and Recovery Capability Validated
- 7. Software Whitelisting and Blacklisting Enforcement Verified
- 8. Inactive Account and Legacy Software Removal Confirmed
- 9. Audit Logging of Installation Events Verified
- 10. Non-Production Testing Evidence Recorded
- About the author
1. Software Installation Policy Formalisation Verified
Verification Criteria: A documented policy defines the rules for installing software on operational systems, including required authorisations and technical constraints.
Required Evidence: Approved “Software Installation Policy” or “Operating System Hardening Standard” with version history.
Pass/Fail Test: If the organisation lacks a formalised mandate restricting who can install software and what types are permitted, mark as Non-Compliant.
2. Least Privilege and Administrative Right Restriction Confirmed
Verification Criteria: Technical controls restrict the ability to install software to a minimal number of authorised administrative accounts.
Required Evidence: Local Administrator group membership reports showing the exclusion of standard user accounts.
Pass/Fail Test: If a standard business user can execute an installer or bypass UAC prompts to install unapproved software, mark as Non-Compliant.
3. Use of Managed Deployment Tools Validated
Verification Criteria: Software installations are performed via centralised management tools rather than manual, ad-hoc execution on production nodes.
Required Evidence: Configuration logs from SCCM, Intune, Jamf, Ansible, or similar automated deployment platforms.
Pass/Fail Test: If the primary method for software updates on production servers is manual RDP/SSH login and file execution, mark as Non-Compliant.
DO IT YOURSELF
ISO 27001
All the templates, tools, support and knowledge you need to do it yourself.
4. Installation Integrity and Digital Signature Verification Confirmed
Verification Criteria: Technical mechanisms verify the authenticity and integrity of software binaries (e.g., checksums or certificates) before installation.
Required Evidence: AppLocker or Windows Defender Application Control (WDAC) logs showing “Publisher” rule enforcement.
Pass/Fail Test: If the system allows the installation of unsigned binaries or packages from unverified third-party sources, mark as Non-Compliant.
5. Operational Change Management Linkage Verified
Verification Criteria: Every software installation on an operational system is cross-referenced with a pre-approved Change Request (CR).
Required Evidence: ITSM ticket logs (e.g., Jira/ServiceNow) matched against system event logs showing the time of installation.
Pass/Fail Test: If a software package was deployed to production without a corresponding, approved Change Request, mark as Non-Compliant.
6. Rollback and Recovery Capability Validated
Verification Criteria: Procedures and technical state-captures (e.g., snapshots) exist to revert the system to a known-good state if an installation fails.
Required Evidence: Pre-deployment checklists requiring a “System Snapshot” or “Full Backup” prior to execution.
Pass/Fail Test: If the organisation cannot demonstrate a technical rollback for the last three major software deployments, mark as Non-Compliant.
7. Software Whitelisting and Blacklisting Enforcement Verified
Verification Criteria: Technical enforcement prevents the execution of unapproved or high-risk software categories (e.g., packet sniffers, hex editors).
Required Evidence: “Allow-list” configuration in the Endpoint Detection and Response (EDR) or AppLocker policy.
Pass/Fail Test: If a blacklisted utility can be executed on an operational server by an authorised admin without a specific exception, mark as Non-Compliant.
8. Inactive Account and Legacy Software Removal Confirmed
Verification Criteria: Unused or legacy software components are removed from operational systems to reduce the attack surface.
Required Evidence: Software inventory delta reports showing the decommissioning of redundant packages or “End of Life” (EOL) software.
Pass/Fail Test: If “End of Life” software remains installed on operational systems without a documented risk acceptance and compensating control, mark as Non-Compliant.
9. Audit Logging of Installation Events Verified
Verification Criteria: Success and failure of software installation events are captured in an immutable central log repository.
Required Evidence: SIEM logs showing Event IDs related to software installation (e.g., Windows Event ID 11707 or 11724).
Pass/Fail Test: If an administrator can install software and then clear the local event log to hide the action, mark as Non-Compliant.
10. Non-Production Testing Evidence Recorded
Verification Criteria: Software is tested in a segregated environment (UAT/Staging) that mirrors production before being installed on operational systems.
Required Evidence: UAT sign-off documents or testing logs identifying the specific software version and hardware compatibility.
Pass/Fail Test: If software is promoted directly to production without documented successful testing in a non-production environment, mark as Non-Compliant.
