Unsupported Software Findernotice of vendor support

8. Unsupported with no owner

The line is past vendor security support (or on extended support only) and the owner column is blank on it, so nobody is named to decide whether it is upgraded, retired or kept.

When it is raised
past support or extended only, and the owner column blank (only when the list has an owner column)
The question
Who owns the decision on this line: upgrade, retire or keep it with an exception?
For
your IT operations lead

The clauses it can cite

ISO/IEC 27001 A.5.9Inventory of information and other associated assets

Inventory of information and other associated assets. The organization is to build and keep current an inventory of its information and other associated assets, with their owners recorded. Purpose (stated in ISO/IEC 27002:2022): identifies the organization's information and associated assets so they can be protected and properly owned. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.9.

What an assessor asks to see: Statement of Applicability entry for control A.5.9, showing inclusion or justified exclusion, implementation status and the risks it treats; The asset inventories (information, hardware, software, virtual, facilities and others) with owner, classification and location fields populated; Reconciliation records between inventories and discovery tooling, or evidence that installs, changes and removals update the inventory automatically; A procedure for assigning ownership on creation or acquisition and reassigning it when owners leave or change role; Records of periodic classification and access restriction reviews carried out by asset owners
Where software lists usually fall short: The inventory covers hardware only and omits information assets, cloud services and software components; Owners listed are people who have left or generic team names with no accountable individual; The inventory drifts from reality because no reconciliation or automated update exists; Disposed assets remain in the inventory, or live assets never entered it
Source: ISO/IEC 27001 (Annex A), read 30 Sep 2026
NIST SP 800-53 CM-8System Component Inventory

CM-8 System Component Inventory. a. Develop and document an inventory of system components that: 1. Accurately reflects the system; 2. Includes all components within the system; 3. Does not include duplicate accounting of components or components assigned to any other system; 4. Is at the level of granularity deemed necessary for tracking and reporting; and 5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and b. Review and update the system component inventory [Assignment: organization-defined frequency].

What an assessor asks to see: Configuration management policy; Procedures addressing system component inventory; Configuration management plan; System security plan; System design documentation; System component inventory; Inventory reviews and update records; Test of Organizational processes for managing the system component inventory; mechanisms supporting and/or implementing system component inventory
Where software lists usually fall short: The component inventory omits components found on the network, or double-counts components assigned to other systems; The inventory lacks the defined accountability information and is not reviewed and updated at the defined frequency
Source: NIST SP 800-53 Rev 5, read 30 Sep 2026

See the specimen list runCheck your own list