Malware protection is to be implemented and backed by appropriate user awareness. Purpose: protect information and associated assets from malware. Guidance: protection combines detection and repair software with awareness, suitable system access and change controls, since detection software alone is rarely enough. Consider: measures that stop or spot unapproved software, such as application allowlisting (8.19, 8.32); controls that prevent or detect visits to sites known or suspected to be malicious, such as blocklists; reducing vulnerabilities malware could exploit through vulnerability management (8.8, 8.19); regular automated validation of system software and data, especially for critical processes, investigating unapproved files or changes; protections against risks from obtaining files and software from or through external networks or other media; installing and keeping updated detection and repair software that scans computers and media, including scanning data received over networks or on media before use, scanning email and messaging attachments and downloads before use at several points such as mail servers, desktops and the network boundary, and scanning web pages when accessed; placing and configuring tools according to risk assessment, applying defence in depth (for example at network gateways for email, file transfer and web, and on endpoints and servers) and accounting for evasion such as encrypted files or encrypted transport; guarding against malware introduced during maintenance and emergency procedures that bypass normal controls; a process to authorize temporary or permanent disabling of protections, with approval authorities, documented justification and a review date; continuity arrangements for recovery after a malware attack with online and offline backups and recovery measures (8.13); isolating environments where outcomes could be catastrophic; procedures and responsibilities for malware protection, including training, reporting and recovery; awareness and training for all users on recognizing and limiting infected emails, files and programs (6.3); regularly gathering information on new malware from mailing lists or relevant sites; and checking that malware warnings come from qualified, reputable sources and are accurate. Other information: some systems such as certain industrial control systems cannot run anti-malware software, and some malware infects operating systems and firmware so deeply that a full reimage, sometimes including firmware, is needed.
This control maps to 147 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1)
E8-APP-ISM-0843 Application control (ISM-0843): Application control is implemented on workstations
E8-APP-ISM-1490 Application control (ISM-1490): Application control is implemented on internet-facing servers
E8-APP-ISM-1544 Application control (ISM-1544): Microsoft’s recommended application blocklist is implemented
E8-APP-ISM-1582 Application control (ISM-1582): Application control rulesets are validated on an annual or more frequent basis
E8-APP-ISM-1656 Application control (ISM-1656): Application control is implemented on non-internet-facing servers
E8-APP-ISM-1657 Application control (ISM-1657): Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set
E8-APP-ISM-1658 Application control (ISM-1658): Application control restricts the execution of drivers to an organisation-approved set
E8-APP-ISM-1659 Application control (ISM-1659): Microsoft’s vulnerable driver blocklist is implemented
E8-APP-ISM-1870 Application control (ISM-1870): Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients
E8-APP-ISM-1871 Application control (ISM-1871): Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients
E8-MACRO-ISM-1487 Restrict Microsoft Office macros (ISM-1487): Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations
E8-MACRO-ISM-1488 Restrict Microsoft Office macros (ISM-1488): Microsoft Office macros in files originating from the internet are blocked
E8-MACRO-ISM-1489 Restrict Microsoft Office macros (ISM-1489): Microsoft Office macro security settings cannot be changed by users
E8-MACRO-ISM-1671 Restrict Microsoft Office macros (ISM-1671): Microsoft Office macros are disabled for users that do not have a demonstrated business requirement
E8-MACRO-ISM-1672 Restrict Microsoft Office macros (ISM-1672): Microsoft Office macro antivirus scanning is enabled
E8-MACRO-ISM-1673 Restrict Microsoft Office macros (ISM-1673): Microsoft Office macros are blocked from making Win32 API calls
E8-MACRO-ISM-1674 Restrict Microsoft Office macros (ISM-1674): Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute
E8-MACRO-ISM-1675 Restrict Microsoft Office macros (ISM-1675): Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View
E8-MACRO-ISM-1676 Restrict Microsoft Office macros (ISM-1676): Microsoft Office’s list of trusted publishers is validated on an annual or more frequent basis
E8-MACRO-ISM-1890 Restrict Microsoft Office macros (ISM-1890): Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations
E8-MACRO-ISM-1891 Restrict Microsoft Office macros (ISM-1891): Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.7 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.