6. One product at several versions, the oldest unsupported
The same product is installed at more than one version and the oldest is past vendor security support (or on extended support only). The finding sits on each line at an unsupported version and names the newest version in the list, which is often already supported and so the quickest to move to.
- When it is raised
- two or more versions of one record in the list, the oldest past its security end date; raised on each line at a version past support or on extended support only
- The question
- Can the older installs move to the version already supported elsewhere in the estate, so one supported version remains?
- For
- your IT operations lead
The clauses it can cite
Cyber Essentials SU.1Software Licensed and SupportedSoftware Licensed and Supported. All software on in-scope devices must be licensed and supported by the vendor (i.e. receiving security updates). Unsupported software must be removed or segregated.
CIS Controls v8 2.1Establish and Maintain a Software InventoryEstablish and Maintain a Software Inventory. Keep a detailed register of all licensed software installed across enterprise assets. Each entry has to capture the title, the publisher, the date of first installation or use, and the business reason for it; where it makes sense, also capture the URL, the app store or stores, the version or versions, how it is deployed, and the date it was retired. Revisit and refresh the register at least twice a year.
CIS Controls v8 2.2Ensure Authorized Software is Currently SupportedEnsure Authorized Software is Currently Supported. Only software that still receives vendor support may be marked as authorised in the enterprise software register. Where unsupported software is still needed for the mission, record an exception that sets out the compensating controls and the acceptance of remaining risk. Unsupported software with no recorded exception is to be marked unauthorised. Check the list for support status no less often than monthly.
NIST SP 800-53 CM-8System Component InventoryCM-8 System Component Inventory. a. Develop and document an inventory of system components that: 1. Accurately reflects the system; 2. Includes all components within the system; 3. Does not include duplicate accounting of components or components assigned to any other system; 4. Is at the level of granularity deemed necessary for tracking and reporting; and 5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and b. Review and update the system component inventory [Assignment: organization-defined frequency].