Skip to main content

💼 A.14.2.4 Restrictions on changes to software packages

  • ID: /frameworks/iso-iec-27001-2013/14/02/04

Description​

Modifications to software packages shall be discouraged, limited to necessary changes and all changes shall be strictly controlled.

Similar​

  • Internal
    • ID: dec-c-4516babf

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v1.1 → 💼 PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity2227no data
💼 NIST CSF v1.1 → 💼 PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g. concept of least functionality)426no data
💼 NIST CSF v1.1 → 💼 PR.IP-3: Configuration change control processes are in place55no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance