Unsupported Software Findernotice of vendor support

CIS Controls v8: what it asks of unsupported software

CIS Safeguard 2.1 asks for a software inventory that records the version; 2.2 lets only software that still receives vendor support be marked authorised, allows an exception with compensating controls and risk acceptance, and asks for the support status to be checked at least monthly; 2.3 asks that unauthorised software is removed or covered by a recorded exception; 7.4 asks for automated application patching at least monthly.

Scheme
CIS Controls v8 (Center for Internet Security)
When it is placed
Placed when you tick CIS Controls v8.
Held text
CIS Controls v8 (Center for Internet Security) on the standards site, read 30 Sep 2026

Findings that cite it

8 of 10

The clauses cited

4 clauses
CIS Controls v8 2.1Establish and Maintain a Software Inventory

Establish and Maintain a Software Inventory. Keep a detailed register of all licensed software installed across enterprise assets. Each entry has to capture the title, the publisher, the date of first installation or use, and the business reason for it; where it makes sense, also capture the URL, the app store or stores, the version or versions, how it is deployed, and the date it was retired. Revisit and refresh the register at least twice a year.

What an assessor asks to see: Software inventory export showing title, publisher, first install date and business purpose for each licensed title; Record of the twice-yearly inventory review; Software asset management standard naming the mandatory inventory fields and the register owner; Sample of software titles traced from endpoints to the register showing publisher and business purpose recorded; Retired software entries showing a decommission date rather than being deleted from the register
Where software lists usually fall short: Register covers workstations but omits servers, cloud workloads or SaaS subscriptions; Business purpose field left blank or filled with a generic value for most titles; Twice-yearly review not held, so the register still lists software removed long ago
Source: CIS Controls v8 (Center for Internet Security), read 30 Sep 2026
CIS Controls v8 2.2Ensure Authorized Software is Currently Supported

Ensure Authorized Software is Currently Supported. Only software that still receives vendor support may be marked as authorised in the enterprise software register. Where unsupported software is still needed for the mission, record an exception that sets out the compensating controls and the acceptance of remaining risk. Unsupported software with no recorded exception is to be marked unauthorised. Check the list for support status no less often than monthly.

What an assessor asks to see: Authorised software list compared with vendor support status, showing only supported software authorised; Exception register for unsupported software with mitigating controls and residual risk acceptance; Monthly support status check record comparing each authorised title with vendor end-of-life announcements; Software register entries for end-of-support titles marked unauthorised where no exception exists; Risk acceptance sign-offs by a named business owner for each unsupported title kept for the mission
Where software lists usually fall short: End-of-life operating systems or Java runtimes still listed as authorised after vendor support ended; Exceptions recorded without compensating controls or an expiry and review date; Support status checked only at annual audit time instead of monthly
Source: CIS Controls v8 (Center for Internet Security), read 30 Sep 2026
CIS Controls v8 2.3Address Unauthorized Software

Address Unauthorized Software. Make sure any unauthorised software on enterprise assets is either taken out of use or covered by a recorded exception, with a review at least monthly.

What an assessor asks to see: Monthly unauthorised software reports and the removal tickets raised; Exception records for any retained unauthorised software, with approval; Endpoint scan comparing installed software with the authorised list, with each unauthorised hit dispositioned; Exception approvals for retained unauthorised software naming the approver and review date; Before and after inventory snapshots confirming unauthorised titles were actually uninstalled
Where software lists usually fall short: Removal tickets closed without verifying the software was uninstalled from every affected device; Unauthorised browser extensions and portable executables never included in the monthly review; Exceptions granted informally by email and absent from any register
Source: CIS Controls v8 (Center for Internet Security), read 30 Sep 2026
CIS Controls v8 7.4Perform Automated Application Patch Management

Perform Automated Application Patch Management. Keep applications on enterprise assets updated by automated patch management, running at least once a month.

What an assessor asks to see: Application patch management configuration with automated monthly deployment; Application patch compliance reports; Patch standard covering third-party applications, not only operating system updates; Third-party patching tool catalogue showing which applications are auto-updated; Monthly application version compliance report for browsers, runtimes, PDF readers and office suites
Where software lists usually fall short: Only Microsoft products patched automatically while Java, Adobe and browsers lag behind; Server-side applications and databases patched only during annual upgrades; Software installed outside the software distribution tool never updated
Source: CIS Controls v8 (Center for Internet Security), read 30 Sep 2026

See the specimen list runCheck your own list