6.3.2 An inventory of bespoke and custom software, and third-party software components incorporated into bespoke and custom software is maintained to facilitate vulnerability and patch management
An inventory of bespoke and custom software, and third-party software components incorporated into bespoke and custom software is maintained to facilitate vulnerability and patch management.
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- External and internal context analysis per assessment · Document repository
governing documentDocuments that govern the control
- Stakeholder map · Document repository
- Relevant objectives · Policy repository / GRC workspace
First move
Common gaps auditors find
- External factors not documented
- Internal culture and capability ignored
- Threat intel not integrated
- Regulatory updates not tracked
- Risk drivers not refreshed
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet6.3.1 Security vulnerabilities are identified and managed as follows: • New security vulnerabilities are identified using industry-recognized sources for security vulnerability information, including alerts from international and national computer emergency response teams (CERTs). • Vulnerabilities · 6.3.3 All system components are protected from known vulnerabilities by installing applicable security patches/updates as follows: • Patches/updates for critical vulnerabilities (identified according to the risk ranking process at Requirement 6.3.1) are installed within one