Skip to content
compliancebase
ISO 27001A.8 — Installation of software on operational systems

A.8.19

Installation of software on operational systems

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Implement procedures to control installation of software on operational systems.

Points of focus

  • Approved software sources
  • Change-controlled installs
  • Immutable infrastructure preference
  • Block unauthorized installs

Implementation notes

Prefer immutable AMIs/containers built in CI. Deny direct package installs on production via IAM and host config. Maintain an allowlist for business apps on endpoints (MDM). Assign a named owner in the SoA, tie operating evidence to software installation procedure, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Show that production changes flow through pipelines and hosts disallow casual installs.

Evidence auditors typically request:

  • Software installation procedure
  • CI/CD deploy records
  • Image pipeline documentation
  • Host hardening preventing manual installs

Common gaps

  • SSH and apt-get on production
  • Untracked browser extensions on admin VMs
  • Golden images never rebuilt

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.8.19This control
SOC 2CC8.1Related SOC 2 themes (CC8.1) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Document break-glass with dual control and post-change review.

Endpoint software installs yes; SaaS procurement is supplier control.

Those cover secure development; A.8.19 is controlling what lands on operational systems.

Even without owned data centers, installation of software on operational systems still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with software installation procedure, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above