ISO/IEC 27001: what it asks of unsupported software
Annex A 5.9 asks for an inventory of information and associated assets with owners recorded; 8.8 asks the organisation to gather information about technical vulnerabilities, assess its exposure and take suitable action; 8.19 asks that installing software on operational systems is managed securely.
- Scheme
- ISO/IEC 27001 (Annex A)
- When it is placed
- Placed when you tick ISO/IEC 27001 as in scope. It is a management system standard you choose to hold, not a law.
- Held text
- ISO/IEC 27001 (Annex A) on the standards site, read 30 Sep 2026
Findings that cite it
8 of 10- 1 Past vendor security support, still installed
- 2 Extended or paid support only
- 3 Ends before your next assessment
- 4 Ends within the window you set
- 7 Not in the lifecycle record
- 8 Unsupported with no owner
- 9 Unsupported with no exception recorded
- 10 Evergreen product behind the current release
The clauses cited
3 clausesISO/IEC 27001 A.5.9Inventory of information and other associated assetsInventory of information and other associated assets. The organization is to build and keep current an inventory of its information and other associated assets, with their owners recorded. Purpose (stated in ISO/IEC 27002:2022): identifies the organization's information and associated assets so they can be protected and properly owned. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.9.
ISO/IEC 27001 A.8.8Management of technical vulnerabilitiesManagement of technical vulnerabilities. The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8.
ISO/IEC 27001 A.8.19Installation of software on operational systemsInstallation of software on operational systems. Procedures and measures are to be put in place so that installing software on operational systems is managed securely. Purpose (stated in ISO/IEC 27002:2022): ensures the integrity of operational systems and prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.19.