View Categories

A8.19 Installation of software on operational systems

4 min read

Installing software directly onto operational systems poses risks such as system instability, vulnerabilities, license non-compliance, and potential malware infection. Operational systems, especially those supporting critical business processes, must be protected from unauthorized or uncontrolled software installations.

ISO 27001 A8.19 Installation of software on operational systems emphasizes that software installation should be strictly controlled and authorized to maintain system integrity, prevent unauthorized changes, and reduce the risk of exploitation or service disruption.

Implementation Guide #

Step 1: Define Software Installation Policies

  • Establish a formal policy outlining who is authorized to install software, under what conditions, and through what processes.
  • Include roles, responsibilities, approval workflows, and required documentation.
    → Tool Recommendation: ServiceNow, Jira Service Management, or Freshservice for approval workflows

Step 2: Restrict Installation Privileges

  • Limit administrative privileges to authorized IT staff only.
  • Prevent end users from installing or executing unauthorized applications.
    → Tool Recommendation:
    – Microsoft Intune or Group Policy for Windows
    – Jamf Pro for macOS
    – Linux sudoers file for UNIX/Linux systems

Step 3: Use Centralized Software Deployment Tools

  • Deploy and manage software through a centralized, secure system that enforces compliance and standardization.
    → Tool Recommendation:
    – Microsoft Endpoint Configuration Manager (SCCM)
    – PDQ Deploy
    – Ansible for configuration-based deployment

Step 4: Approve and Test Software Before Installation

  • Conduct security and compatibility testing in a non-production (sandbox or staging) environment.
  • Require sign-off from relevant stakeholders (e.g., IT security, system owners).
    → Tool Recommendation: Sandboxie, VMware Workstation, or VirtualBox for isolated testing environments

Step 5: Maintain Installation Logs and Audit Trails

  • Document every software installation event, including installer, version, date/time, and approval reference.
  • Regularly review logs to detect unauthorized installations.
    → Tool Recommendation: Sysmon with SIEM tools (e.g., Splunk, LogRhythm), OSQuery

Step 6: Conduct Regular Software Audits

  • Periodically audit installed software across operational systems.
  • Identify unauthorized or outdated software and take corrective action.
    → Tool Recommendation: Lansweeper, SolarWinds Software Asset Management, Qualys Asset Inventory

Templates #

  • Software Installation Request Form
  • Software Installation Policy
  • Approved Software Inventory List
  • Installation Log Template
  • Change Management Approval Record

Example #

A healthcare provider allowed local installation rights to senior staff for convenience. One user unintentionally installed outdated software with a known vulnerability, resulting in a data breach. The organization responded by enforcing centralized deployment using Microsoft Intune, removing local admin rights, and implementing a software approval workflow through ServiceNow. This eliminated unauthorized installations and ensured all software was tested and approved before deployment.

How to Comply #

To comply with ISO 27001 A.8.19, organizations should:

  • Establish and enforce a software installation policy.
  • Use controlled and approved processes for all installations.
  • Limit installation rights to authorized personnel.
  • Maintain records of installations and approvals.
  • Regularly audit installed software and system configurations.

How to Pass an Audit #

Key Documents to Prepare:

  • Software Installation Policy and Procedures
  • Role-Based Access Control Matrix
  • Software Installation Logs and Change Records
  • Software Inventory Reports
  • Testing and Approval Records for Installed Software

What the Auditor Will Check:

  • Are installation rights limited and well-controlled?
  • Is there a documented and followed process for software approval?
  • Are unauthorized installations detected and remediated?
  • Are audit logs and records available and complete?

Top 3 Mistakes People Make #

  • Allowing users administrative rights, leading to uncontrolled software installations.
  • Failing to document software changes or approvals.
  • Not testing software for security and compatibility before deployment.

ISO 27001 Software Installation FAQ #

Q1: Can we allow team leads to install tools they need quickly?
Only if they have been granted controlled and monitored administrative access, and the tools are pre-approved and safe. Ideally, such requests should go through a formal process.

Q2: Is freeware or open-source software subject to the same controls?
Yes. All software—regardless of cost—should be reviewed for security, compatibility, and licensing before installation.

Q3: What if emergency software installation is required?
Have an emergency change procedure in place, which includes post-installation review and retroactive approval.

ISO 27001 Controls and Attribute Values #

Control Attribute Value
A.8.19 Installation of Software on Operational Systems Preventive, Operational, Risk-Based
Purpose Prevent unauthorized or insecure software from compromising system integrity and business operations.
Applicability All operational systems, including servers, endpoints, and production environments.
ISO 27001 Domains Operations Security, System Acquisition, Development and Maintenance

By tightly controlling software installation on operational systems, organizations can reduce risks of unauthorized access, system compromise, and non-compliance, ensuring more stable and secure IT operations.

Leave a Reply

Your email address will not be published. Required fields are marked *

Log in

You dont have an account yet? Register Now