An inventory that reflects what software platforms and applications are being used in the organization shall be documented, reviewed, and updated when changes occur.
The inventory of software platforms and applications associated with information and information processing shall reflect changes in the organization’s context and include all information necessary for effective accountability.
Individuals who are responsible and who are accountable for administering software platforms and applications within the organization shall be identified.
When unauthorized software is detected, it shall be quarantined for possible exception handling, removed, or replaced, and the inventory shall be updated accordingly.
Mechanisms for detecting the presence of unauthorized software within the organization’s ICT/OT environment shall be identified.