COBIT 2019
Deliver, Service and Support – COBIT 2019

COBIT 2019 DSS05.01: DSS05.01 Protect against malicious software

Measures that prevent, detect and correct, above all current security patches and virus control, are put in place and kept up throughout the enterprise to shield information systems and technology from malware, ransomware, viruses, worms, spyware and spam: protection tools against malicious software are installed and running on every processing facility, with their definition files updated automatically or semi-automatically; incoming traffic, email and downloads for example, is filtered against unsolicited content such as spyware and phishing; awareness of malicious software is communicated and prevention procedures and responsibilities enforced, with periodic training on malware in email and internet use and users taught to report suspicious items instead of opening them; protection software is distributed centrally at a controlled version and patch level through configuration and change management; and information on new threats, such as security advisories from vendors, is reviewed regularly.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 2 controls

  • 8.7 Protection against malware
  • 8.8 Management of technical vulnerabilities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Deliver, Service and Support – COBIT 2019

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.