7. Not in the lifecycle record
The product, or this version of it, is not in the lifecycle record held here (endoflife.date, read on the date shown). That says nothing about its support: it is unknown, never supported. The clauses you ticked ask you to know the answer, so the answer comes from the vendor.
- When it is raised
- no record matches the product name, or the record does not list the version, or the version is not given or is shared by several releases
- The question
- Check with the vendor: is this version still receiving security updates, and until when? Record the answer and its source beside the line.
- For
- your IT operations lead
The clauses it can cite
Cyber Essentials SU.1Software Licensed and SupportedSoftware Licensed and Supported. All software on in-scope devices must be licensed and supported by the vendor (i.e. receiving security updates). Unsupported software must be removed or segregated.
CIS Controls v8 2.1Establish and Maintain a Software InventoryEstablish and Maintain a Software Inventory. Keep a detailed register of all licensed software installed across enterprise assets. Each entry has to capture the title, the publisher, the date of first installation or use, and the business reason for it; where it makes sense, also capture the URL, the app store or stores, the version or versions, how it is deployed, and the date it was retired. Revisit and refresh the register at least twice a year.
CIS Controls v8 2.2Ensure Authorized Software is Currently SupportedEnsure Authorized Software is Currently Supported. Only software that still receives vendor support may be marked as authorised in the enterprise software register. Where unsupported software is still needed for the mission, record an exception that sets out the compensating controls and the acceptance of remaining risk. Unsupported software with no recorded exception is to be marked unauthorised. Check the list for support status no less often than monthly.
PCI DSS 4.0 12.3.4Annual review of hardware and software technologies12.3.4 Annual review of hardware and software technologies. Hardware and software in use must undergo a check at least every 12 months, covering at minimum: analysis that vendors still supply timely security fixes; analysis that the technologies still support, and do not obstruct, PCI DSS compliance; documentation of industry announcements or trends about a technology, for instance a vendor's end-of-life notice; and a remediation plan for outdated technologies, including those with announced end-of-life, approved by senior management. Objective under the customized approach: hardware and software stay current and vendor supported, and plans to retire or replace unsupported components are reviewed periodically. Future-dated: treated as a best practice up to 31 March 2025 and mandatory since then.
NIST SP 800-53 CM-8System Component InventoryCM-8 System Component Inventory. a. Develop and document an inventory of system components that: 1. Accurately reflects the system; 2. Includes all components within the system; 3. Does not include duplicate accounting of components or components assigned to any other system; 4. Is at the level of granularity deemed necessary for tracking and reporting; and 5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and b. Review and update the system component inventory [Assignment: organization-defined frequency].
ISO/IEC 27001 A.5.9Inventory of information and other associated assetsInventory of information and other associated assets. The organization is to build and keep current an inventory of its information and other associated assets, with their owners recorded. Purpose (stated in ISO/IEC 27002:2022): identifies the organization's information and associated assets so they can be protected and properly owned. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.9.