ISO 27001 Annex A 8.19 sets clear rules for installing software on live systems. Tracking every change through standard business tools stops unapproved updates from causing disruption.
Table of contents
Key Takeaways
- Establish Software Rules: Maintain clear policies defining strict conditions and prerequisites for installing software on live operational systems.
- Enforce Approval Workflows: Require formal authorization from designated management before deploying any software, patch, or system update to production.
- Test Prior to Deployment: Verify all software updates, code changes, and patches thoroughly in an isolated test environment before live installation.
- Restrict Admin Privileges: Limit software installation permissions strictly to authorized administrative accounts to block unsanctioned installations.
- Maintain Central Inventories: Keep an accurate register of all deployed software versions, operational systems, and third-party tools in shared repositories.
- Implement Rollback Plans: Document clear back-out and rollback procedures for every deployment to restore system integrity quickly if failures occur.
- Track Deployment Logs: Record complete change histories, deployment timestamps, and ticket sign-offs for all production updates to maintain auditability.
- Control System Baselines: Monitor operational system builds regularly to detect and remove unauthorized software or unapproved application updates.
How to Implement ISO 27001 Annex A 8.19
- Draft Installation Policies: Write a clear software deployment policy and store it in a version-controlled central library.
- Define Deployment Roles: Identify authorized technical personnel and record their specific roles and privileges in a central staff matrix.
- Build Change Request Workflows: Route all software installation requests through formal work tickets with mandatory risk assessment and rollback fields.
- Test Before Production: Execute thorough functional and security testing in an isolated staging environment and attach test reports to the change ticket.
- Require Pre-Deployment Approvals: Enforce mandatory sign-offs from designated management before any code, update, or software is deployed live.
- Maintain System Version Logs: Update your internal wiki and asset inventory with the latest release details and system build numbers immediately after deployment.
- Lock Local Endpoint Rights: Standardise local system privileges to ensure standard employees cannot install unapproved third-party software on company devices.
- Automate Deployment Tracking: Configure deployment tools to log precise installation timestamps, change IDs, and executor details directly into work tickets.
How to Audit ISO 27001 Annex A 8.19
- Inspect Deployment Policies: Review the formal software installation policy to confirm defined rules, approval requirements, and rollback procedures are active and approved.
- Verify Deployment Roles: Sample the staff role matrix and system permissions to ensure only designated technical leads hold live software installation rights.
- Sample Change Workflows: Examine a random selection of recent change tickets to confirm mandatory risk assessment and rollback plan fields were completed.
- Review Staging Test Evidence: Inspect pre-deployment test logs and security scan reports attached to change tickets to verify staging tests were executed before release.
- Check Management Sign-Offs: Verify that change tickets show documented approval from authorized leads prior to deployment into production.
- Audit System Build Logs: Cross-reference live software build numbers against the asset inventory and internal wiki to ensure system version records match production.
- Test Endpoint Rights Restrictions: Sample standard employee laptops to verify administrative privilege blocks stop unauthorized software downloads and installations.
- Verify Automated Deployment Logs: Inspect deployment pipeline logs to confirm installation timestamps, executor accounts, and change IDs are automatically captured.
- Verify Rollback Plan Execution: Sample failed or aborted deployment tickets to ensure rollback procedures were triggered effectively without leaving operational systems in an unstable state.
- Audit Emergency Hotfix Procedures: Review emergency deployment logs to confirm emergency software updates underwent retrospective security testing and management sign-off within specified timeframes.
Audit Evidence Checklist
Focus on manual records that prove human oversight and intent. Your evidence must reside in your internal repositories. This demonstrates active management of the ISMS.
- Software Installation Policy: Provide a version-controlled document in SharePoint defining clear rules, approval thresholds, and testing prerequisites for deploying operational software.
- Approved Change Tickets: Supply complete change request records in Jira featuring detailed risk assessments, deployment schedules, and formal management sign-offs.
- Rollback Procedures: Present documented back-out plans in Confluence detailing step-by-step recovery actions should a live software deployment fail.
- Pre & Post-Installation Test Reports: Attach staging test logs, security scan outputs, and post-deployment validation reports proving system functionality was verified.
- Change Advisory Board (CAB) Minutes: Produce formal meeting records showing regular leadership review, risk evaluation, and approval of upcoming production software releases.
- System Integrity Verification Logs: Show automated pipeline logs and baseline audit records confirming software build versions match approved release tickets.
- Endpoint Privileged Access Proof: Share administrative policy settings demonstrating that standard user accounts are restricted from installing unauthorized third-party applications.
What to Teach Employees
- Follow Software Installation Rules: Teach staff why installing unapproved software on company devices creates security risks and violates company policy.
- Use Approved App Stores: Show workers how to request and install software using official, pre-approved company software catalogs or IT ticket workflows.
- Understand Endpoint Privilege Restrictions: Explain to employees why local administrator rights are restricted to prevent unauthorized background software changes.
- Submit Change Requests for Production Code: Train developers and technical leads to route all live software updates through formal ticket approvals before deployment.
- Test Changes in Staging Environments: Ensure engineers practice deploying and verifying software updates in staging environments prior to production release.
- Verify Pre-Deployment Approvals: Remind deployment staff never to execute production releases without verified sign-offs from authorized team managers.
- Update Inventory Logs After Releases: Show deployment operators how to log updated software build numbers and release details in the internal asset wiki.
- Report Unsanctioned Software Warnings: Train staff to report pop-up alerts or unexpected software installation prompts to the IT security team right away.
- Prepare Documented Rollback Plans: Teach technical operators always to have a tested back-out plan ready before launching live software updates.
Common Implementation Challenges
- Automated Complacency: Caused by relying on a SaaS platform dashboard tick without keeping an internal work trail. Fix this by implementing a formal change request workflow in your internal work tracking system immediately.
- Lack of Authorisation: Caused by installing software without documented approval from a designated manager. Fix this by enforcing sign-off requirements in your central installation policy.
- No Rollback Plan: Caused by updating live systems without a documented way to undo changes if something breaks. Fix this by mandating detailed rollback procedures for all change tickets.
- Untested Production Deployments: Caused by pushing software updates directly to live systems without prior verification. Fix this by requiring staging test results and security scan reports attached to every change ticket before release.
- Unsanctioned Endpoint Installations: Caused by users downloading unapproved software onto local workstations. Fix this by locking administrative installation privileges and deploying pre-approved corporate application catalogs.
- Emergency Hotfix Bypass: Caused by skipping authorization and logging rules during urgent system outages. Fix this by implementing an expedited emergency change process that requires retrospective review and log sign-off within 24 hours.
How to Measure Effectiveness (KPIs)
- Unauthorized Installation Count: Tracks the number of unapproved software applications detected on company endpoints or servers during routine automated scans.
- Deployment Change Approval Rate: Measures the percentage of production software releases that received formal management sign-off prior to deployment.
- Failed Deployment Rollback Rate: Tracks the percentage of software installations or updates that failed in production and required immediate rollback.
- Pre-Deployment Test Coverage: Measures the percentage of software updates that underwent documented functional and security testing in staging environments before release.
- Unapproved Privilege Escalation Events: Counts instances where users attempted or succeeded in bypassing local endpoint restrictions to install software.
- Asset Inventory Sync Rate: Tracks how accurately the internal software register and wiki reflect active production versions and release numbers following deployments.
- Emergency Deployment Ratio: Measures the percentage of software updates deployed via emergency pathways versus planned change requests to identify underlying release stability issues.
- Post-Deployment Incident Rate: Tracks the number of security or operational incidents triggered directly by recent software releases within 48 hours of deployment.
Related ISO 27001 Controls
Annex A 8.19 connects to several core ISO 27001 requirements:
- ISO 27001 Clause 8.1: Operational planning and control of changes.
- ISO 27001 Annex A 8.32: Change management integration.
- ISO 27001 Annex A 8.31: Separation of development: test: and production environments.
- ISO 27001 Annex A 8.13: Information backup before installation.


