Skip to content

Procedure To Control The Installation Of Software On Operational System

Procedure to control the installation of software on operational system

Version history

Version Number Date Description Created By Approved By
0.1 23/Apr/2024 Initial Copy [Name]
0.2 18/Jun/2024 Approved [Name] [Name]
0.3 28/Aug/2026 Knowledge kernel, AI/agents, control alignment Knowledge steward [Name]

Purpose

  • This policy outlines the requirements to be met on company-owned computing devices. The aim is to minimize the risk of loss of program functionality and exposure of sensitive.

  • information contained within the tecciance computing network, the risk of introducing malware, and the legal exposure of running unlicensed software.

Scope

  • This policy applies to all tecciance employees, contractors, and vendors with tecciance -owned devices. It covers all computers, servers, smartphones, tablets, and other computing devices operating within tecciance.

Policy

  • Employees should not install any software on tecciance workstations (laptops/desktops) operated within the organization’s network.

  • Software requests must first be approved by the requester’s manager and then be made available to the ICT (Information and Communications Technology) department through the ticketing tool or via email.

  • Only the ICT team is authorized to install approved software into the user systems. At the time of issuing the systems to users, ICT will install the Operating System and other standard applications like MS Office, Document reader, Antivirus, and Archiving Software, etc., which are approved software by management.

  • Software must be selected from an approved software list, maintained by the ICT department unless no selection on the list meets the requester’s needs. A request for new procurement will be initiated. Proper procurement formalities shall be met for procuring these types of requirements.

  • ICT will obtain and track the licenses, test new software for conflict and compatibility, and perform the installation. Compliance with third-party software audits is taken care of by maintaining purchased software versus installed software and monitoring the unauthorized installation of software by users monthly.

  • Along with the request, the intender needs to mention the justification of the need, the purpose of the software, and the duration of the requirement, and the type of license that needs to be incorporated. This option will save the company on costs, which may vary for perpetual versus cloud licenses.

  • Software Asset Management compliances are recorded on a quarterly basis, and deviations are reported to management for either purchasing the required software or uninstalling the same.

List of Approved Software

S.No. Software Name
1

M365 Apps for Business

2

Google Chrome

3

Zoom

4

AnyDesk

5

TeamViewer

6

Adobe Acrobat

7

OneDrive

8

MS Teams

Artificial intelligence, software agents, and organizational knowledge

This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.

Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.

Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.

AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.

Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.

Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.

Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.

HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.

Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.

Installation includes agent tools, IDE plugins, MCP servers, and model runtimes. Only allowlisted tools may run against organization or client code.