A.8.19 Installation of software on operational systems
Securely manage software installation on production systems.
12
artefacts
3
held by a system
2
at each review
moderate
to go live
Ticketing / ITSM
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- IT Service Management ticket detailing requested software · Ticketing / ITSM
- System installation log generated by the deployment tool · SIEM / log platform
- Security scan result after software deployment · Vulnerability scanner / patch tooling
periodic reviewEvidence produced at each review
- Change Management approval record · Ticketing / ITSM
- Risk assessment worksheet attached to the change request · Ticketing / ITSM
governing documentDocuments that govern the control
- Software Installation Request Form · Policy repository / GRC workspace
- Business justification document for the software · Document repository
- Manager sign‑off email · Document repository
- Package deployment script used for the installation · Policy repository / GRC workspace
- CMDB entry update showing the new software version · Policy repository / GRC workspace
- Post‑installation validation report confirming functionality · Document repository
- Rollback test record demonstrating recovery procedure · Policy repository / GRC workspace
First move
Start with the 3 of 12 artefacts that already live in a system (Ticketing / ITSM); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Missing formal approval for installations
- No evidence of post‑install verification
- Reliance on informal requests instead of documented tickets
- Failure to update inventory of installed software
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.8.18 Use of privileged utility programs · A.8.20 Networks security