N.4.07 Keeping software on company assets up to date
Control Overview
This control mandates that the organization establishes, implements, and enforces a formalized patch and configuration management policy to ensure that all software running on company assets remains continuously secure and updated. Software vulnerabilities represent one of the primary entry vectors for malicious actors. To mitigate this risk, the organization must implement automated deployment mechanisms, define explicit patch remediation timelines based on vulnerability severity, and actively govern the installation of software across all corporate endpoints and operational cloud environments.
Applicability Note: This control is fully applicable to the anDREa platform and is a vital baseline defense protecting our distributed endpoint fleet and live cloud infrastructure from zero-day exploits and known vulnerabilities.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, combining automated endpoint enforcement with structured patch management Service Level Agreements (SLAs).
anDREa tackles software lifecycle risk through two separate automated tracks:
- Endpoint Protection: Operating under our A.06.07 - Remote working, all user devices utilize built-in operational system mechanics to download and force-install critical security patches automatically, minimizing the window of exposure without requiring user intervention.
- Infrastructure Environment: For the operational systems and containerized stacks powering the myDRE platform, tracking is managed through A.08.08 - Management of technical vulnerabilities.
To satisfy NIS 2 oversight expectations, our framework avoids vague update windows by enforcing explicit patch remediation SLAs directly inside our vulnerability management policy. These SLAs dictate strict, time-bound completion windows (e.g., immediate 24–72 hour windows for critical exploits) to ensure high-priority security definitions are applied rapidly across the ecosystem.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.08.19 - Installation of software on operational systems | Mandates strict operational governance regarding how, when, and by whom software updates are tested and deployed onto live production environments. |
| ISO/IEC 27001 | A.08.08 - Management of technical vulnerabilities | Defines the core vulnerability management lifecycles, scanning cadences, and the explicit patch remediation SLAs required for system hardening. |
| ISO/IEC 27001 | A.06.07 - Remote working | Extends mandatory automated operating system patching and application update constraints down to remote worker endpoints. |
| Operational Governance | Monthly CTO Security Reports | Formal management dashboards that track patch compliance metrics, pending software lifecycle updates, and exception logs. (Management Reports) |
| Infrastructure Records | Cloud Environment Patch Logs | Verifiable deployment histories and automation scripts within our cloud orchestration layer proving that runtime systems are running securely hardened configurations. (Patching Performance) |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Automated user endpoint patching, cloud infrastructure lifecycle rules, and explicit patch remediation timelines (SLAs) within Annex A.8.8 are completely operationalized and auditable.