💼 A.14.2.4 Restrictions on changes to software packages
- Contextual name: 💼 A.14.2.4 Restrictions on changes to software packages
- ID:
/frameworks/iso-iec-27001-2013/14/02/04
- Located in: 💼 A.14.2 Security in development and support processes
Description​
Modifications to software packages shall be discouraged, limited to necessary changes and all changes shall be strictly controlled.
Similar​
- Internal
- ID:
dec-c-4516babf
- ID:
Similar Sections (Give Policies To)​
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
💼 NIST CSF v1.1 → 💼 PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity | 22 | 26 | ||
💼 NIST CSF v1.1 → 💼 PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality) | 4 | 26 | ||
💼 NIST CSF v1.1 → 💼 PR.IP-3: Configuration change control processes are in place | 5 | 5 |
Sub Sections​
Section | Sub Sections | Internal Rules | Policies | Flags |
---|