Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

N.4.07 Keeping software on company assets up to date

Control Overview

This control mandates that the organization establishes, implements, and enforces a formalized patch and configuration management policy to ensure that all software running on company assets remains continuously secure and updated. Software vulnerabilities represent one of the primary entry vectors for malicious actors. To mitigate this risk, the organization must implement automated deployment mechanisms, define explicit patch remediation timelines based on vulnerability severity, and actively govern the installation of software across all corporate endpoints and operational cloud environments.

note

Applicability Note: This control is fully applicable to the anDREa platform and is a vital baseline defense protecting our distributed endpoint fleet and live cloud infrastructure from zero-day exploits and known vulnerabilities.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, combining automated endpoint enforcement with structured patch management Service Level Agreements (SLAs).

anDREa tackles software lifecycle risk through two separate automated tracks:

  1. Endpoint Protection: Operating under our A.06.07 - Remote working, all user devices utilize built-in operational system mechanics to download and force-install critical security patches automatically, minimizing the window of exposure without requiring user intervention.
  2. Infrastructure Environment: For the operational systems and containerized stacks powering the myDRE platform, tracking is managed through A.08.08 - Management of technical vulnerabilities.

To satisfy NIS 2 oversight expectations, our framework avoids vague update windows by enforcing explicit patch remediation SLAs directly inside our vulnerability management policy. These SLAs dictate strict, time-bound completion windows (e.g., immediate 24–72 hour windows for critical exploits) to ensure high-priority security definitions are applied rapidly across the ecosystem.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.19 - Installation of software on operational systemsMandates strict operational governance regarding how, when, and by whom software updates are tested and deployed onto live production environments.
ISO/IEC 27001A.08.08 - Management of technical vulnerabilitiesDefines the core vulnerability management lifecycles, scanning cadences, and the explicit patch remediation SLAs required for system hardening.
ISO/IEC 27001A.06.07 - Remote workingExtends mandatory automated operating system patching and application update constraints down to remote worker endpoints.
Operational GovernanceMonthly CTO Security ReportsFormal management dashboards that track patch compliance metrics, pending software lifecycle updates, and exception logs. (Management Reports)
Infrastructure RecordsCloud Environment Patch LogsVerifiable deployment histories and automation scripts within our cloud orchestration layer proving that runtime systems are running securely hardened configurations. (Patching Performance)

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Automated user endpoint patching, cloud infrastructure lifecycle rules, and explicit patch remediation timelines (SLAs) within Annex A.8.8 are completely operationalized and auditable.