PlumbTrackLive demoGRC Risk System

← internal audit

Audit — SA-22 — Unsupported System Components

Framework: NIST SP 800-53 Rev.5 SA-22 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the hardware and software asset inventory to confirm each component records its vendor end-of-life (EOL) / end-of-support (EOS) date, and that components past EOS are explicitly flagged as unsupported (CIS Controls v8 2.2 - ensure authorized software is currently supported).
Examine Examine the organization's list of unsupported / end-of-life system components and verify each entry has a documented disposition - either a scheduled replacement date or an approved alternative-support arrangement per SA-22a/SA-22b.
Test Test the automated inventory / vulnerability scanning capability by running or observing a scan and confirming it detects and reports end-of-life or unsupported operating systems, firmware, and application versions (CIS Controls v8 7 - continuous vulnerability management).
Examine Examine the alternative-support arrangement for any component retained past vendor EOS (in-house support plan or an extended / third-party support contract) and confirm it is currently active and covers security-relevant patches and updates.
Interview Interview procurement/acquisition staff and system owners to confirm a defined process tracks vendor support timelines and triggers a replacement-or-alternative-support decision before a component reaches EOS.
Examine Examine the Plan of Action and Milestones (POA&M) to verify unsupported components that cannot be immediately replaced have a documented risk acceptance, compensating controls, and authorizing official approval.
Test Test a sample of production systems by observing patch/version status to confirm no component is running an operating system or software version past vendor end-of-support without an approved, documented exception.