Content library
Cyber Essentials
SUM-02: Keeping licensed software up to date

How to fill the requirement

Cyber Essentials

SUM-02: Keeping licensed software up to date

Task name
Priority
Status
Theme
Policy
Other requirements
Keeping licensed software up to date
Critical
High
Normal
Low
Fully done
Mostly done
Partly done
Not done
System management
Data system management
requirements

Task is fulfilling also these other security requirements

SUM-02: Keeping licensed software up to date
Cyber Essentials
Article 9: Prevention
DORA
1. Task description

The organisation has to make sure that all licensed software are updated with in 14 days of the update coming live when:

  • The update fixes vulnerabilities that are considered critical or high risk
  • Supplier does not release details about the severity of the vulnerability
Authorized users and rules for installing software and libraries
Critical
High
Normal
Low
Fully done
Mostly done
Partly done
Not done
Development and cloud
Technical vulnerability management
requirements

Task is fulfilling also these other security requirements

12.6.2: Restrictions on software installation
ISO27 Full
SUM-02: Keeping licensed software up to date
Cyber Essentials
DE.CM-5: Unauthorized mobile code detection
NIST
TEK-17: Muutoshallintamenettelyt
Julkri
8.19: Installation of software on operational systems
ISO27k1 Full
1. Task description

Unmanaged installations of software on computers can lead to vulnerabilities and security breaches.

The organization should determine what types of software or updates each user can install. The instructions may include e.g. the following guidelines:

  • only specially designated persons may install new software on the devices
  • programs previously designated as secure may be installed by anyone
  • use of certain software may be impossible for everyone
  • existing software updates and security patches are allowed to be installed by anyone
No items found.