CIS Control 2: Inventory and Control of Software Assets
Summary
Establishing a baseline of installed software enables an organization to respond to active threats, avoid license violations, and identify unnecessary security risks. Many options exist for defining precise allowlist to govern what software, libraries, or scripts may execute on a system. Where appropriate, it must also include the Uniform Resource Locator (URL), app store(s), version(s), deployment mechanism, and decommission date. If software is unsupported yet necessary for the fulfillment of the enterprise’s mission, document an exception detailing mitigating controls and residual risk acceptance. Reassess bi-annually or more frequently Notes: Script interpreters are often needed for standard software installations and administrative tasks, but they can present a large security gap for an attacker.