Freeware software on product environment
Assign topic to the user
Answer: ISO 27001:2013 does not define what can or cannot be allowed/accessed in an organization, but requires that any decision made is based on the results of a risk assessment, applicable legal requirements and top management decision. So, you should consult these sources to verify if you can allow/access freeware on production environment.
What I can tell you is that some freeware have licenses that forbids them to use in commercial environments (you have to use the paid version), so you should consult the terms of the software you are considering.
This article will provide you further explanation about software installation:
- Implementing restrictions on software installation using ISO 27001 control A.12.6.2 https://advisera.com/27001academy/blog/2016/02/08/implementing-restrictions-on-software-installation-using-iso-27001-control-a-12-6-2/
These materials will a lso help you regarding software installation:
- ISO 27001 Annex A Controls in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
Comment as guest or Sign in
Aug 20, 2017