PR.PS-05 Installation and execution of unauthorized software are prevented
Installation and execution of unauthorized software are prevented.
5
artefacts
1
held by a system
1
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Unauthorized software detection alerts · SIEM / log platform
periodic reviewEvidence produced at each review
- Periodic review of installed software baselines · Document repository
governing documentDocuments that govern the control
- Application allowlist policy and tooling configuration · Policy repository / GRC workspace
- Endpoint protection deployment reports · Policy repository / GRC workspace
- Software install request workflow · Document repository
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your SIEM / log platform on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Allowlist exceptions overgrown
- Detection alerts only for sanctioned populations
- Install workflow bypassed by admins
- Review of installed software not performed
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetPR.PS-04 Log records are generated and made available for continuous monitoring · PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle