Skip to content
arrow_back
search
Annex A 8.19 verified ISO/IEC 27001:2022

Secure Software Installation Procedures

Ensure software installations are controlled to prevent security risks.

record_voice_over

Plain language

This control is about making sure that whenever software is installed on company computers, it's done in a way that keeps everything safe and secure. If this isn't done properly, it could lead to vulnerable systems that hackers could exploit, which might result in stolen data or disrupted operations.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

12 Apr 2026

Maturity levels

N/A

Official control statement

Procedures and measures shall be implemented to securely manage software installation on operational systems.
verified ISO/IEC 27001:2022 Annex A 8.19
priority_high

Why it matters

Without controlled software installation, unauthorised apps can introduce security holes and malware, risking data breaches and operational failures.

settings

Operational notes

Only install approved, signed software from trusted repositories; require change approval, least-privilege installers, and log installs with tested rollback/uninstall steps.

Mapping detail

Mapping

Direction

Controls