ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.7: Protection against malware

Malware protection is to be implemented and backed by appropriate user awareness. Purpose: protect information and associated assets from malware. Guidance: protection combines detection and repair software with awareness, suitable system access and change controls, since detection software alone is rarely enough. Consider: measures that stop or spot unapproved software, such as application allowlisting (8.19, 8.32); controls that prevent or detect visits to sites known or suspected to be malicious, such as blocklists; reducing vulnerabilities malware could exploit through vulnerability management (8.8, 8.19); regular automated validation of system software and data, especially for critical processes, investigating unapproved files or changes; protections against risks from obtaining files and software from or through external networks or other media; installing and keeping updated detection and repair software that scans computers and media, including scanning data received over networks or on media before use, scanning email and messaging attachments and downloads before use at several points such as mail servers, desktops and the network boundary, and scanning web pages when accessed; placing and configuring tools according to risk assessment, applying defence in depth (for example at network gateways for email, file transfer and web, and on endpoints and servers) and accounting for evasion such as encrypted files or encrypted transport; guarding against malware introduced during maintenance and emergency procedures that bypass normal controls; a process to authorize temporary or permanent disabling of protections, with approval authorities, documented justification and a review date; continuity arrangements for recovery after a malware attack with online and offline backups and recovery measures (8.13); isolating environments where outcomes could be catastrophic; procedures and responsibilities for malware protection, including training, reporting and recovery; awareness and training for all users on recognizing and limiting infected emails, files and programs (6.3); regularly gathering information on new malware from mailing lists or relevant sites; and checking that malware warnings come from qualified, reputable sources and are accurate. Other information: some systems such as certain industrial control systems cannot run anti-malware software, and some malware infects operating systems and firmware so deeply that a full reimage, sometimes including firmware, is needed.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 147 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ACSC Essential Eight · 23 controls

  • E8-APP-ML1 Application Control (ML1)
  • E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1)
  • E8-APP-ISM-0843 Application control (ISM-0843): Application control is implemented on workstations
  • E8-APP-ISM-1490 Application control (ISM-1490): Application control is implemented on internet-facing servers
  • E8-APP-ISM-1544 Application control (ISM-1544): Microsoft’s recommended application blocklist is implemented
  • E8-APP-ISM-1582 Application control (ISM-1582): Application control rulesets are validated on an annual or more frequent basis
  • E8-APP-ISM-1656 Application control (ISM-1656): Application control is implemented on non-internet-facing servers
  • E8-APP-ISM-1657 Application control (ISM-1657): Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set
  • E8-APP-ISM-1658 Application control (ISM-1658): Application control restricts the execution of drivers to an organisation-approved set
  • E8-APP-ISM-1659 Application control (ISM-1659): Microsoft’s vulnerable driver blocklist is implemented
  • E8-APP-ISM-1870 Application control (ISM-1870): Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients
  • E8-APP-ISM-1871 Application control (ISM-1871): Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients
  • E8-MACRO-ISM-1487 Restrict Microsoft Office macros (ISM-1487): Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations
  • E8-MACRO-ISM-1488 Restrict Microsoft Office macros (ISM-1488): Microsoft Office macros in files originating from the internet are blocked
  • E8-MACRO-ISM-1489 Restrict Microsoft Office macros (ISM-1489): Microsoft Office macro security settings cannot be changed by users
  • E8-MACRO-ISM-1671 Restrict Microsoft Office macros (ISM-1671): Microsoft Office macros are disabled for users that do not have a demonstrated business requirement
  • E8-MACRO-ISM-1672 Restrict Microsoft Office macros (ISM-1672): Microsoft Office macro antivirus scanning is enabled
  • E8-MACRO-ISM-1673 Restrict Microsoft Office macros (ISM-1673): Microsoft Office macros are blocked from making Win32 API calls
  • E8-MACRO-ISM-1674 Restrict Microsoft Office macros (ISM-1674): Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute
  • E8-MACRO-ISM-1675 Restrict Microsoft Office macros (ISM-1675): Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View
  • E8-MACRO-ISM-1676 Restrict Microsoft Office macros (ISM-1676): Microsoft Office’s list of trusted publishers is validated on an annual or more frequent basis
  • E8-MACRO-ISM-1890 Restrict Microsoft Office macros (ISM-1890): Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations
  • E8-MACRO-ISM-1891 Restrict Microsoft Office macros (ISM-1891): Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View

CIS Controls v8 · 16 controls

  • CIS-10.1 Deploy and Maintain Anti-Malware Software
  • CIS-10.2 Configure Automatic Anti-Malware Signature Updates
  • CIS-10.3 Disable Autorun and Autoplay for Removable Media
  • CIS-10.4 Configure Automatic Anti-Malware Scanning of Removable Media
  • CIS-10.5 Enable Anti-Exploitation Features
  • CIS-10.6 Centrally Manage Anti-Malware Software
  • CIS-10.7 Use Behavior-Based Anti-Malware Software
  • CIS-13.3 Deploy a Network Intrusion Detection Solution
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution
  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-2.7 Allowlist Authorized Scripts
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
  • CIS-9.2 Use DNS Filtering Services
  • CIS-9.6 Block Unnecessary File Types
  • CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections

PCI DSS 4.0 · 14 controls

  • 1.5.1 1.5.1 Security controls on dual-connected devices
  • 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic
  • 11.5.1.1 11.5.1.1 Service providers detect covert malware channels
  • 12.10.5 12.10.5 Plan covers alerts from security monitoring systems
  • 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency
  • 5.3.5 5.3.5 Users cannot disable or alter anti-malware
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing
  • 5.2.1 5.2.1 Anti-malware deployed on all system components
  • 5.2.2 5.2.2 Anti-malware detects and handles all known malware
  • 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware
  • 5.3.1 5.3.1 Anti-malware kept current through automatic updates
  • 5.3.2 5.3.2 Periodic and real-time scans or continuous behavioural analysis
  • 5.3.3 5.3.3 Anti-malware covers removable electronic media
  • 6.4.3 6.4.3 Payment page script management

FedRAMP High · 11 controls

  • CM-7(2) Prevent Program Execution
  • CM-7(5) Authorized Software Allow-by-Exception
  • IR-4(1) Automated Incident Handling Processes
  • MA-3(2) Maintenance Tools | Inspect Media (MA-3(2))
  • SC-18 Mobile Code
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SI-3 Malicious Code Protection
  • SI-7 Software, Firmware, and Information Integrity
  • SI-8 Spam Protection
  • SI-8(2) Spam Protection | Automatic Updates (SI-8(2))
  • SR-10 Inspection of Systems or Components (SR-10)

FedRAMP Moderate · 11 controls

  • CM-7(2) Prevent Program Execution
  • CM-7(5) Authorized Software Allow-by-Exception
  • IR-4(1) Automated Incident Handling Processes
  • MA-3(2) Maintenance Tools | Inspect Media (MA-3(2))
  • SC-18 Mobile Code
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SI-3 Malicious Code Protection
  • SI-7 Software, Firmware, and Information Integrity
  • SI-8 Spam Protection
  • SI-8(2) Spam Protection | Automatic Updates (SI-8(2))
  • SR-10 Inspection of Systems or Components (SR-10)
  • ASD37-01 Application control (Essential)
  • ASD37-03 Configure Microsoft Office macro settings (Essential)
  • ASD37-05 Automated dynamic analysis of email and web content (Excellent)
  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-15 User education (Limited)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-24 Non-persistent virtualised sandboxed environment (Very Good)
  • ASD37-30 Endpoint detection and response (Very Good)

NIST SP 800-53 Rev 5 · 8 controls

CMMC 2.0 · 6 controls

  • ASBv3-AM-5 Use only approved applications in virtual machine
  • ASBv3-ES-3 Ensure anti-malware software and signatures are updated
  • ASBv3-GS-9 Define and implement endpoint security strategy
  • ES-1 Use Endpoint Detection and Response (EDR)
  • ES-2 Use modern anti-malware software
  • ISM-0341 Disabling automatic execution for removable media
  • ISM-1234 Filtering email bodies and attachments
  • ISM-1341 HIPS or EDR on workstations
  • ISM-1417 Antivirus application configuration

UK Cyber Essentials · 4 controls

  • CE-MP.1 Anti-Malware Software Deployed
  • CE-MP.2 Anti-Malware Signatures Updated
  • CE-MP.3 Anti-Malware Scans Files on Access and Web Pages
  • CE-MP.4 Application Allowlisting (Alternative)
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented
  • NIST-CSF-RS.MI-02 Incidents are eradicated

SOC 2 · 3 controls

  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies

C5 (Germany) · 2 controls

  • C5-OPS-04 Protection Against Malware - Concept
  • C5-OPS-05 Protection Against Malware - Implementation

IEC 62443 · 2 controls

  • 62443-2-4-SP-05 Service Provider Malware Protection Practices
  • 62443-3-3-FR3-SR-3-2 Protection from Malicious Code

ISO 27701:2019 · 2 controls

  • 6.9.2 Protection from malware
  • 7.4.6 Temporary files

MTCS (Singapore) · 2 controls

  • 14.3 Malicious code prevention
  • 14.4 Portable code

NIST SP 800-171 Rev 3 · 2 controls

  • 12.7.20.C.05 12.7.20.C.05 Malware check code needed by equipment
  • 18.4.10.C.01 18.4.10.C.01 Malicious code policies and procedures
  • AUCDR-IS-5 Limit, prevent, detect and remove malware

DORA · 1 control

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 8.7 Protection against malware

NIST SP 800-172 · 1 control

  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

NY DFS 23 NYCRR 500 · 1 control

  • P1-4.1.2 P1-4.1.2 Anti-malware controls active and maintained

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 147 it maps to, and the evidence behind each claim, over MCP and REST.