CIS Controls v8: what it asks of unsupported software
CIS Safeguard 2.1 asks for a software inventory that records the version; 2.2 lets only software that still receives vendor support be marked authorised, allows an exception with compensating controls and risk acceptance, and asks for the support status to be checked at least monthly; 2.3 asks that unauthorised software is removed or covered by a recorded exception; 7.4 asks for automated application patching at least monthly.
- Scheme
- CIS Controls v8 (Center for Internet Security)
- When it is placed
- Placed when you tick CIS Controls v8.
- Held text
- CIS Controls v8 (Center for Internet Security) on the standards site, read 30 Sep 2026
Findings that cite it
8 of 10- 1 Past vendor security support, still installed
- 2 Extended or paid support only
- 3 Ends before your next assessment
- 4 Ends within the window you set
- 6 One product at several versions, the oldest unsupported
- 7 Not in the lifecycle record
- 9 Unsupported with no exception recorded
- 10 Evergreen product behind the current release
The clauses cited
4 clausesCIS Controls v8 2.1Establish and Maintain a Software InventoryEstablish and Maintain a Software Inventory. Keep a detailed register of all licensed software installed across enterprise assets. Each entry has to capture the title, the publisher, the date of first installation or use, and the business reason for it; where it makes sense, also capture the URL, the app store or stores, the version or versions, how it is deployed, and the date it was retired. Revisit and refresh the register at least twice a year.
CIS Controls v8 2.2Ensure Authorized Software is Currently SupportedEnsure Authorized Software is Currently Supported. Only software that still receives vendor support may be marked as authorised in the enterprise software register. Where unsupported software is still needed for the mission, record an exception that sets out the compensating controls and the acceptance of remaining risk. Unsupported software with no recorded exception is to be marked unauthorised. Check the list for support status no less often than monthly.
CIS Controls v8 2.3Address Unauthorized SoftwareAddress Unauthorized Software. Make sure any unauthorised software on enterprise assets is either taken out of use or covered by a recorded exception, with a review at least monthly.
CIS Controls v8 7.4Perform Automated Application Patch ManagementPerform Automated Application Patch Management. Keep applications on enterprise assets updated by automated patch management, running at least once a month.