End of Life Procedures for Software
Create and share procedures for removing software and managing user accounts at its end of life.
Plain language
This control is all about having a clear plan for what to do when software we use reaches its 'end of life,' meaning it's no longer supported or updated. This is important because outdated software can be a security risk, leaving us vulnerable to attacks and data breaches.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for software developmentOfficial control statement
End of life procedures for software, including procedures for software removal and the archival or destruction of user accounts and data, are produced and made available to consumers.
Why it matters
Without proper procedures for retiring software, organisations risk using insecure systems, leading to potential data breaches or operational disruptions.
Operational notes
Keep track of approaching software end-of-life dates and start planning transitions early to avoid disruptions.
Implementation tips
- Managers should work with their IT team to identify software nearing end of life. They can do this by checking software providers' updates and support timelines, and setting reminders for review well before support ends.
- IT teams should create clear procedures for removing software safely. This involves listing steps to uninstall the software and ensuring that no components are left running on any devices.
- HR should collaborate with IT to make sure all user accounts associated with end-of-life software are properly managed. This means archiving needed data and removing access to protect company information.
- System owners must ensure alternative software solutions are planned and tested before current software is retired. Engage with users to verify new options meet business needs.
- Procurement should keep records of all software and its lifecycle status. This can be done with a simple spreadsheet, logging purchase dates, version details, and end-of-life dates.
Audit / evidence tips
- Askthe software inventory list: Request a document showing all software in use and its end-of-life datesLook atcompleteness and updated entriesGooda current inventory showing recent reviews and actions for end-of-life software
- Askthe organisation's decommissioning procedure: See the steps laid out for safely removing softwareLook atclear sequences, responsible persons, and security considerationsGooda comprehensive document tested and approved by key stakeholders
- Look attime-stamped actions with responsible person notedGoodlogs showing systematic deactivation in line with policies
- Look atevidence of trials or pilot testsGooddocumented plans showing user feedback and planned go-live dates
- Askto see the communication sent to staff about software changes: Check that details about software removal and new software instructions were shared well in advanceGoodemails or memos that clearly explain the change timeline and actions required by staff
Cross-framework mappings
How ISM-2053 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(2)expand_less | ||
| Annex A 5.16 | ISM-2053 requires organisations to define end-of-life procedures for software, including how to archive or destroy user accounts and asso... | |
| Annex A 8.10 | ISM-2053 requires documented software EOL procedures that explain how to remove retired software and how to archive or destroy related us... | |
handshakeSupports(1)expand_less | ||
| Annex A 7.14 | ISM-2053 covers end-of-life procedures for software, indirectly supporting Annex A 7.14 by addressing licensed software management during... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Software development
See all Guidelines for software development controls, or browse the full ASD ISM library.