Oh no! No description found. But not to worry. Read from Tasks below how to advance this topic.
Identify the software in use at the organisation in accordance with the process described in 1.2.1. a) Identify firmware, operating system and applications (name, version number, manufacturer, installation date, whether it is still supported) installed on servers, clients and network equipment etc. b) Create a plan for how to approve software for use at the organisation (see 1.2.2). The process described above can be simplified by being consistent in allowlisting all applications (especially clients) (alternatively the use of app stores). Systematic use of application allowlists (or app stores) can make it easier to maintain an inventory of software in use. This is particularly relevant for end user clients.
Identify the software in use at the organisation in accordance with the process described in 1.2.1. a) Identify firmware, operating system and applications (name, version number, manufacturer, installation date, whether it is still supported) installed on servers, clients and network equipment etc. b) Create a plan for how to approve software for use at the organisation (see 1.2.2). The process described above can be simplified by being consistent in allowlisting all applications (especially clients) (alternatively the use of app stores). Systematic use of application allowlists (or app stores) can make it easier to maintain an inventory of software in use. This is particularly relevant for end user clients.
In Cyberday, requirements and controls are mapped to universal tasks. A set of tasks in the same topic create a Policy, such as this one.
In Cyberday, requirements and controls are mapped to universal tasks. Each requirement is fulfilled with one or multiple tasks.
When building an ISMS, it's important to understand the different levels of information hierarchy. Here's how Cyberday is structured.
Sets the overall compliance standard or regulation your organization needs to follow.
Break down the framework into specific obligations that must be met.
Concrete actions and activities your team carries out to satisfy each requirement.
Documented rules and practices that are created and maintained as a result of completing tasks.