data.gift
  • Datasets

http://cyfun.data.gift/data/requirement_PR_PS_02_1

http://cyfun.data.gift/data/requirement_PR_PS_02_1
Concept

  • http://cyfun.data.gift/data/CyFun2025

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_delta_BASIC_to_IMPORTANT

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_IMPORTANT

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

    • External link
    • Internal link

  • http://cyfun.data.gift/data/subcategory_PR.PS-02

    • External link
    • Internal link

Properties and relations

Direct links from the subject.

Property Value

type

The subject is an instance of a class.

  • External link
  • Internal link

http://cyfun.data.gift/ontology#Requirement

  • External link
  • Internal link

type

The subject is an instance of a class.

  • External link
  • Internal link

Concept

An idea or notion; a unit of thought.

  • External link
  • Internal link

label

A human-readable name for the subject.

  • External link
  • Internal link

PR.PS-02.1: The organisation shall enforce restrictions on software usage and installation, and ensure that software is maintained, replaced, or removed based on its associated risk.

http://cyfun.data.gift/ontology#requirementId

  • External link
  • Internal link

PR.PS-02.1

http://cyfun.data.gift/ontology#foundIn

  • External link
  • Internal link

http://cyfun.data.gift/data/loc_CyFun2025_Booklet_ESSENTIAL_E_p123

  • External link
  • Internal link

http://cyfun.data.gift/ontology#foundIn

  • External link
  • Internal link

http://cyfun.data.gift/data/loc_CyFun2025_Booklet_IMPORTANT_E_p85

  • External link
  • Internal link

has broader

Relates a concept to a concept that is more general in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_PR.PS-02

  • External link
  • Internal link

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to reduce security and operational risks by controlling which software is used, ensur- ing it is properly maintained, and removing it when no longer needed or supported. To achieve this goal, the organisation should consider to: • Allow only approved software and restrict access based on user roles and responsibilities. • Replace unsupported or end-of-life software to avoid unpatched vulnerabilities. • Uninstall unused or unnecessary software, including outdated OS utilities, to reduce the attack surface. • Apply patches based on risk: o Critical vulnerabilities should be patched within hours. o Routine updates should follow a defined schedule (e.g. weekly or monthly). • In container environments, only trusted and up-to-date images should be used; outdated containers should be replaced. • Remove or disable software and services that pose unacceptable risk, such as FTP or peer-to-peer tools, unless explicitly required and secured. • In ICS/OT environments, ensure PLC programming is pre-approved and scheduled; avoid ad-hoc changes to protect operational safety. • Maintain a software inventory with version and support status. • Define procedures for software approval, patching, replacement, and removal.

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to reduce security and operational risks by controlling which software is used, ensur- ing it is properly maintained, and removing it when no longer needed or supported. To achieve this goal, the organisation should consider to: - Allow only approved software and restrict access based on user roles and responsibilities. - Replace unsupported or end-of-life software to avoid unpatched vulnerabilities. - Uninstall unused or unnecessary software, including outdated OS utilities, to reduce the attack surface. - Apply patches based on risk: - Critical vulnerabilities should be patched within hours. - Routine updates should follow a defined schedule (e.g. weekly or monthly). - In container environments, only trusted and up-to-date images should be used; outdated containers should be replaced. - Remove or disable software and services that pose unacceptable risk, such as FTP or peer-to-peer tools, unless explicitly required and secured. - In ICS/OT environments, ensure PLC programming is pre-approved and scheduled; avoid ad-hoc changes to protect operational safety. - Maintain a software inventory with version and support status. - Define procedures for software approval, patching, replacement, and removal.

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to reduce security and operational risks by controlling which software is used, ensur- ing it is properly maintained, and removing it when no longer needed or supported. To achieve this goal, the organisation should consider to: - Allow only approved software and restrict access based on user roles and responsibilities. - Replace unsupported or end-of-life software to avoid unpatched vulnerabilities. - Uninstall unused or unnecessary software, including outdated OS utilities, to reduce the attack surface. - Apply patches based on risk: - Critical vulnerabilities should be patched within hours. - Routine updates should follow a defined schedule (e.g. weekly or monthly). - In container environments, only trusted and up-to-date images should be used; outdated containers should be replaced. - Remove or disable software and services that pose unacceptable risk, such as FTP or peer-to-peer tools, unless explicitly required and secured. - In ICS/OT environments, ensure PLC programming is pre-approved and scheduled; avoid ad-hoc changes to protect operational safety. - Maintain a software inventory with version and support status. - Define procedures for software approval, patching, replacement, and removal.

note

A general note, for any purpose.

  • External link
  • Internal link

<div><p>The goal of this control is to reduce security and operational risks by controlling which software is used, ensur- ing it is properly maintained, and removing it when no longer needed or supported. To achieve this goal, the organisation should consider to:</p><ul><li>Allow only approved software and restrict access based on user roles and responsibilities.</li><li>Replace unsupported or end-of-life software to avoid unpatched vulnerabilities.</li><li>Uninstall unused or unnecessary software, including outdated OS utilities, to reduce the attack surface.</li><li>Apply patches based on risk:<ul><li>Critical vulnerabilities should be patched within hours.</li><li>Routine updates should follow a defined schedule (e.g. weekly or monthly).</li></ul></li><li>In container environments, only trusted and up-to-date images should be used; outdated containers should be replaced.</li><li>Remove or disable software and services that pose unacceptable risk, such as FTP or peer-to-peer tools, unless explicitly required and secured.</li><li>In ICS/OT environments, ensure PLC programming is pre-approved and scheduled; avoid ad-hoc changes to protect operational safety.</li><li>Maintain a software inventory with version and support status.</li><li>Define procedures for software approval, patching, replacement, and removal.</li></ul></div>

notation

A notation, also known as classification code, is a string of characters such as "T58.5" or "303.4833" used to uniquely identify a concept within the scope of a given concept scheme.

  • External link
  • Internal link

PR.PS-02.1

alternative label

skos:prefLabel, skos:altLabel and skos:hiddenLabel are pairwise disjoint properties.

  • External link
  • Internal link

Software usage and installation restrictions

preferred label

A resource has no more than one value of skos:prefLabel per language tag, and no more than one value of skos:prefLabel without language tag.

  • External link
  • Internal link

The organisation shall enforce restrictions on software usage and installation, and ensure that software is maintained, replaced, or removed based on its associated risk.

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_delta_BASIC_to_IMPORTANT

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_IMPORTANT

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

  • External link
  • Internal link

http://cyfun.data.gift/ontology#level

  • External link
  • Internal link

http://cyfun.data.gift/data/level_IMPORTANT

  • External link
  • Internal link

triple count

The number of triples associated with the subject.

  • External link
  • Internal link

19

in dataset

Specifies the dataset the subject is part of.

  • External link
  • Internal link

http://data.gift/d/datasets/69E8863AA6CE46D9ACD13109

  • External link
  • Internal link

Resultaten 1 - 21 of 21

References

Inverse links to the subject.

Property Subject

http://cyfun.data.gift/ontology#hasRequirement

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_PR.PS-02

  • External link
  • Internal link

has narrower

Relates a concept to a concept that is more specific in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_PR.PS-02

  • External link
  • Internal link

Resultaten 1 - 1 of 1

© 2024 redpencil.io. All rights reserved.