Unsupported Software Findernotice of vendor support

ISO/IEC 27001: what it asks of unsupported software

Annex A 5.9 asks for an inventory of information and associated assets with owners recorded; 8.8 asks the organisation to gather information about technical vulnerabilities, assess its exposure and take suitable action; 8.19 asks that installing software on operational systems is managed securely.

Scheme
ISO/IEC 27001 (Annex A)
When it is placed
Placed when you tick ISO/IEC 27001 as in scope. It is a management system standard you choose to hold, not a law.
Held text
ISO/IEC 27001 (Annex A) on the standards site, read 30 Sep 2026

Findings that cite it

8 of 10

The clauses cited

3 clauses
ISO/IEC 27001 A.5.9Inventory of information and other associated assets

Inventory of information and other associated assets. The organization is to build and keep current an inventory of its information and other associated assets, with their owners recorded. Purpose (stated in ISO/IEC 27002:2022): identifies the organization's information and associated assets so they can be protected and properly owned. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.9.

What an assessor asks to see: Statement of Applicability entry for control A.5.9, showing inclusion or justified exclusion, implementation status and the risks it treats; The asset inventories (information, hardware, software, virtual, facilities and others) with owner, classification and location fields populated; Reconciliation records between inventories and discovery tooling, or evidence that installs, changes and removals update the inventory automatically; A procedure for assigning ownership on creation or acquisition and reassigning it when owners leave or change role; Records of periodic classification and access restriction reviews carried out by asset owners
Where software lists usually fall short: The inventory covers hardware only and omits information assets, cloud services and software components; Owners listed are people who have left or generic team names with no accountable individual; The inventory drifts from reality because no reconciliation or automated update exists; Disposed assets remain in the inventory, or live assets never entered it
Source: ISO/IEC 27001 (Annex A), read 30 Sep 2026
ISO/IEC 27001 A.8.8Management of technical vulnerabilities

Management of technical vulnerabilities. The organization is to gather information about technical vulnerabilities in the information systems it uses, assess how exposed it is, and take suitable action. Purpose (stated in ISO/IEC 27002:2022): prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.8.

What an assessor asks to see: Statement of Applicability entry for control A.8.8, showing inclusion or justified exclusion, implementation status and the risks it treats; A software asset inventory with vendor, product, version, deployment location and responsible owner; Defined vulnerability management roles and a list of monitored vulnerability information sources; Authenticated scan results and penetration test reports by authorized testers, with verification scans after patching; Remediation timelines by severity with measured performance, and risk records weighing the vulnerability against update risk
Where software lists usually fall short: The asset inventory is incomplete, so unknown software is never scanned or patched; Remediation timelines are routinely missed with no risk acceptance; Third-party libraries in in-house code are not tracked for vulnerabilities; There is no way for external researchers to report vulnerabilities
Source: ISO/IEC 27001 (Annex A), read 30 Sep 2026
ISO/IEC 27001 A.8.19Installation of software on operational systems

Installation of software on operational systems. Procedures and measures are to be put in place so that installing software on operational systems is managed securely. Purpose (stated in ISO/IEC 27002:2022): ensures the integrity of operational systems and prevents exploitation of technical vulnerabilities. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.19.

What an assessor asks to see: Statement of Applicability entry for control A.8.19, showing inclusion or justified exclusion, implementation status and the risks it treats; Procedures for installing and updating operational software, including authorization, testing and rollback planning; Change and deployment records showing management authorization, successful testing and the administrator who performed the installation; Configuration control records for operational software and documentation, and an audit log of updates; Evidence that development tools and compilers are absent from production systems
Where software lists usually fall short: Users can install any software on servers or workstations; Production systems contain compilers and development code; Unsupported software versions remain in production without a risk decision; Externally hosted dependencies are pulled at build or run time without integrity controls
Source: ISO/IEC 27001 (Annex A), read 30 Sep 2026

See the specimen list runCheck your own list