8. Unsupported with no owner
The line is past vendor security support (or on extended support only) and the owner column is blank on it, so nobody is named to decide whether it is upgraded, retired or kept.
- When it is raised
- past support or extended only, and the owner column blank (only when the list has an owner column)
- The question
- Who owns the decision on this line: upgrade, retire or keep it with an exception?
- For
- your IT operations lead
The clauses it can cite
ISO/IEC 27001 A.5.9Inventory of information and other associated assetsInventory of information and other associated assets. The organization is to build and keep current an inventory of its information and other associated assets, with their owners recorded. Purpose (stated in ISO/IEC 27002:2022): identifies the organization's information and associated assets so they can be protected and properly owned. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.9.
NIST SP 800-53 CM-8System Component InventoryCM-8 System Component Inventory. a. Develop and document an inventory of system components that: 1. Accurately reflects the system; 2. Includes all components within the system; 3. Does not include duplicate accounting of components or components assigned to any other system; 4. Is at the level of granularity deemed necessary for tracking and reporting; and 5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and b. Review and update the system component inventory [Assignment: organization-defined frequency].