This section of the standard requires that your organisation manages the security updates for end user devices, servers and networking devices ( routers and firewalls) in line with the standard, which requires a security update to be pushed within 14 days of release.

This section is also interested in ensuring that your devices are licensed appropriately and that your organisation has removed all the software that is no longer supported or end of life.

In the case of A6.7 if your organisation uses software that is unsupported you will need to place it in a separate VLAN with no internet access and the scope of Whole Organisation cannot be achieved.

Untitled