CIS-8.1.2.2 — Ensure Authorized Software is Currently SupportedDomain: CIS Control 2 | Safeguard: CIS-8.1.2.2 | Asset Class: Software | Security Function: Identify | Source: CIS Controls v8.1.2 (March 2025) |
Implementation Groups: IG1IG2IG3 Ensure that only currently supported software is designated as authorized in the software inventory for enterprise assets. If software is unsupported, yet necessary for the fulfillment of the enterprise's mission, document an exception detailing mitigating controls and residual risk acceptance. For any unsupported software without an exception documentation, designate as unauthorized. Review the software list to verify software support at least monthly, or more frequently. |
Tags: CIS-8.1.2.2, cis-controls, cis-v8-1, ig3, control-2, asset-class-software, function-identify