CIS-8.1.2.2 — Ensure Authorized Software is Currently SupportedDomain: CIS Control 2 | Safeguard: CIS-8.1.2.2 | Asset Class: Software | Security Function: Identify | Source: CIS Controls v8.1.2 (March 2025) |
Implementation Groups: IG1IG2IG3 Ensure that only currently supported software is designated as authorized in the software inventory. |
Executive Summary (For Leadership and the Board)
CIS Safeguard CIS-8.1.2.2 sits inside Control 2 (Software / Identify). Mature programs treat this as a measured, recertified, and audit-evidenced control. The Safeguard maps to NIST SP 800-53 Rev. 5 CM-7, CM-10/11, SI-7 and to NIST CSF 2.0 ID.AM, PR.PS.
Tags: CIS-8.1.2.2, cis-controls, cis-v8-1, ig3, control-2, asset-class-software, function-identify