Frameworks / ASD Strategies to Mitigate Cyber Security Incidents / ASD37-12 ASD Strategies to Mitigate Cyber Security Incidents
Preventing Malware Delivery and Execution
ASD Strategies to Mitigate Cyber Security Incidents ASD37-12: Antivirus software with heuristics (Very Good) Antivirus software using heuristics and reputation ratings to check a file's prevalence and digital signature prior to execution.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 90 controls across 66 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
5.2.1 5.2.1 Anti-malware deployed on all system components 5.2.2 5.2.2 Anti-malware detects and handles all known malware 5.3.2 5.3.2 Periodic and real-time scans or continuous behavioural analysis ES-1 Use Endpoint Detection and Response (EDR) ES-2 Use modern anti-malware software C5-OPS-04 Protection Against Malware - Concept C5-OPS-05 Protection Against Malware - Implementation CIS-10.1 Deploy and Maintain Anti-Malware Software CIS-10.7 Use Behavior-Based Anti-Malware Software NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented CE-MP.1 Anti-Malware Software Deployed CE-MP.3 Anti-Malware Scans Files on Access and Web Pages E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1) API1164-12 Incident Response AWWA-4.1 Malware Protection CJIS-10 System and Information Integrity CAT-D3-1 Preventative controls FFIEC-07 Endpoint protection and detection SI-3 Malicious Code Protection SI-3 Malicious Code Protection GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines HKMA-SPM-TM-Technology-TM-G-1-CRAF-Coord HKMA SPM Technology Management Modules (TM-G-1 to TM-G-4, TM-E-1) + Coordination with C-RAF IEC62443-12 Malware prevention for operational systems IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability 8.7 Protection against malware 8.7 Protection against malware 27010-12.2 Protection from malware 27011-8.5 Vulnerability and malware management ISO27019-12 Malware prevention for operational systems ISO27043-22 Protection from malware ISO21434-22 Protection from malware MAS-TRM-Project-SDLC-Service-Management-Chapters-4-5-6-IT-Project-Software-Lifecycle-Change-ITIL MAS TRM Project + SDLC + Service Management + Chapters 4-6 + IT Project + Software Lifecycle + ITIL NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management OMANCS-5 Network, Endpoint, System Development, and Configuration Security OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-4 Security Policy, Vulnerability Disclosure, Responsible Reporting PCI-P2PE-07 Endpoint protection and detection PCI-PIN-07 Endpoint protection and detection PCI-SSF-07 Endpoint protection and detection PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PTESPHASE-3 Threat Modeling SHAREASSESS-4 Vulnerability Management, Patching, Application Security SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software UKGAMBLE-4 Resilience and Incident Response CYB-3 Device Security Measures Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Preventing Malware Delivery and Execution You are reading one control. How much of ASD Strategies to Mitigate Cyber Security Incidents have you already done? ASD Strategies to Mitigate Cyber Security Incidents ASD37-12 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ASD Strategies to Mitigate Cyber Security Incidents your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 32 of 37 ASD Strategies to Mitigate Cyber Security Incidents controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 90 it maps to, and the evidence behind each claim, over MCP and REST.