A.8.19 Installation of Software on Operational Systems
Control Objective
Procedures and measures shall be implemented to securely manage software installation on operational systems.
Policy Statement
anDREa strictly regulates the installation of software across all operational infrastructure, corporate endpoints, and tenant-provisioned virtual environments. Uncontrolled software installation introduces substantial risks, including malware execution, licensing breaches, and baseline instability. System configurations enforce technical blocks to ensure only authorized, pre-vetted packages can be deployed.
Software Installation Governance
The execution and management of software installations are separated across our corporate and platform layers:
- Corporate Endpoints: The installation of applications, browser extensions, and technical utilities on anDREa-managed devices or approved BYOD environments is governed strictly under A.06.07 - Remote working. Users lack permanent local administrative privileges, and software deployment is restricted via centralized Mobile Device Management (MDM) application whitelists.
- Research Virtual Environments (myDRE Workspaces): Operating under our Shared Responsibility Model, software deployment within deployed research Virtual Machines (VMs) is technically ring-fenced using Role-Based Access Control (RBAC) (see: myDRE Role Matrix).
- General workspace participants are blocked from modifying system files or executing installers.
- Software installation capabilities are restricted exclusively to authorized Accountable Members, Privileged Members, and Advanced Members within that specific project boundary.