01 · Explanation
Devices, updates, and approved software
Objective: Maintain a visible baseline for supported devices and software using secure configuration, timely updates, protection, encryption, and controlled exceptions.
An organization cannot protect devices it does not know about. Record owner, user, device identifier, operating system, support status, encryption, screen lock, endpoint protection, backup coverage, administrator rights, and last review. Separate ordinary user activity from administrative access. Use organization-managed devices for sensitive work where required and define whether personal devices are permitted, what data they may access, and how lost or departed devices are handled. Physical control matters: unattended screens, shared family devices, and unencrypted removable media can bypass otherwise strong online controls.
Use supported software from approved sources and apply security updates within risk-based targets. Critical exploited vulnerabilities may require faster action, but updates should still follow tested change and rollback procedures appropriate to the system. Remove unused applications, browser extensions, local administrators, and end-of-life devices. An exception should name the business reason, risk owner, compensating controls, expiration, and replacement plan. Do not run scanners, exploit tools, or configuration changes against systems without authorization. Complex infrastructure, vulnerability management, mobile-device management, and regulated environments require qualified technical specialists and vendor-specific guidance.
Before you begin
- Confirm F03, F06, and F07; record that the device identifier, network location, endpoint telemetry, approved forensic playbook, clean device, evidence image, isolation status, and recovery authorization are not supplied.
- STOP. If device identity, network location, telemetry, forensic playbook, trusted tooling, evidence image, or isolation status is missing or conflicts with F03/F06/F07, route the branch to authorized incident leadership and the forensic/endpoint owner; do not claim recovery approval or execute isolation, cleanup, rebuild, or return to service.

