Software implementations, patches, updates and new installations have the potential to impact PII and privacy-related assets in a myriad of ways.
Organisations need to take great care when installing applications, utility programs and executable code on operational systems.
ISO 27701 clause 6.9.5 contains just one sub-clause (ISO 27701 6.9.5.1) that deals solely with the installation of software on operational systems.
There are no additional PIMS or PII-related guidance points, nor are there any linked UK GDPR articles to consider.
In order to protect the availability and integrity of PII, and administer change, organisations should:
When utilising vendor-supplied software, applications should be kept in good working order and in accordance with the issuers guidelines.
ISO makes it explicitly clear that organisations should avoid using unsupported software unless absolutely necessary. Organisations should seek to upgrade incumbent systems, rather than use out-of-date or unsupported legacy applications.
A vendor may require access to an organisation’s network in order to perform an installation or update. Such activities should be authorised and monitored at all times (see ISO 27002 Control 5.22).
Book a tailored hands-on session
based on your needs and goals
Book your demo
ISO 27701 Clause Identifier | ISO 27701 Clause Name | ISO 27002 Control | Associated GDPR Articles |
---|---|---|---|
6.9.5.1 | Installation of Software on Operational Systems | 8.19 – Installation of Software on Operational Systems for ISO 27002 | None |
You must create a Privacy Information Management System (PIMS) to meet ISO 27701 standards. Using our preconfigured PIMS, you can quickly and easily organise and manage customer, supplier, and employee information to fully meet ISO 27701 standards.
ISMS.online can also accommodate the growing number of global, regional, and sector-specific privacy regulations.
You must first become ISO 27001 (information security) certified to achieve ISO 27701 (privacy) certification. Fortunately, our platform can assist you with both of these certifications.
Find out more by booking a demo.
ISMS.online is a
one-stop solution that radically speeded up our implementation.
Request a quote