Measures that prevent, detect and correct, above all current security patches and virus control, are put in place and kept up throughout the enterprise to shield information systems and technology from malware, ransomware, viruses, worms, spyware and spam: protection tools against malicious software are installed and running on every processing facility, with their definition files updated automatically or semi-automatically; incoming traffic, email and downloads for example, is filtered against unsolicited content such as spyware and phishing; awareness of malicious software is communicated and prevention procedures and responsibilities enforced, with periodic training on malware in email and internet use and users taught to report suspicious items instead of opening them; protection software is distributed centrally at a controlled version and patch level through configuration and change management; and information on new threats, such as security advisories from vendors, is reviewed regularly.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.