Skip to main content

💼 A.14.2.4 Restrictions on changes to software packages

Description​

Modifications to software packages shall be discouraged, limited to necessary changes and all changes shall be strictly controlled.

Similar​

  • Internal
    • ID: dec-c-4516babf

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
💼 NIST CSF v1.1 → 💼 PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity2226
💼 NIST CSF v1.1 → 💼 PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality)426
💼 NIST CSF v1.1 → 💼 PR.IP-3: Configuration change control processes are in place55

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags