EvidenceSheet

A.8.19 Installation of software on operational systems

Securely manage software installation on production systems.

12
artefacts
3
held by a system
2
at each review
moderate
to go live
Ticketing / ITSM
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • IT Service Management ticket detailing requested software · Ticketing / ITSM
  • System installation log generated by the deployment tool · SIEM / log platform
  • Security scan result after software deployment · Vulnerability scanner / patch tooling

periodic reviewEvidence produced at each review

  • Change Management approval record · Ticketing / ITSM
  • Risk assessment worksheet attached to the change request · Ticketing / ITSM

governing documentDocuments that govern the control

  • Software Installation Request Form · Policy repository / GRC workspace
  • Business justification document for the software · Document repository
  • Manager sign‑off email · Document repository
  • Package deployment script used for the installation · Policy repository / GRC workspace
  • CMDB entry update showing the new software version · Policy repository / GRC workspace
  • Post‑installation validation report confirming functionality · Document repository
  • Rollback test record demonstrating recovery procedure · Policy repository / GRC workspace

First move

Start with the 3 of 12 artefacts that already live in a system (Ticketing / ITSM); keep the periodic reviews but log each one as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

A.8.18 Use of privileged utility programs · A.8.20 Networks security