NIST SP 800-66 Rev 2
Administrative

NIST SP 800-66 Rev 2 164.308(a)(5)(ii)(B): Protection from Malicious Software (Addressable)

Implement procedures for guarding against, detecting, and reporting malicious software. NIST recommends endpoint protection, email filtering, web filtering, and user reporting channels.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 94 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 12 controls

  • CIS-10.1 Deploy and Maintain Anti-Malware Software
  • CIS-10.2 Configure Automatic Anti-Malware Signature Updates
  • CIS-10.4 Configure Automatic Anti-Malware Scanning of Removable Media
  • CIS-10.6 Centrally Manage Anti-Malware Software
  • CIS-10.7 Use Behavior-Based Anti-Malware Software
  • CIS-13.10 Perform Application Layer Filtering
  • CIS-2.3 Address Unauthorized Software
  • CIS-2.6 Allowlist Authorized Libraries
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
  • CIS-9.3 Maintain and Enforce Network-Based URL Filters
  • CIS-9.6 Block Unnecessary File Types
  • CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections

PCI DSS 4.0 · 10 controls

  • 1.2.6 1.2.6 Security features for insecure services in use
  • 11.2.1 11.2.1 Detect authorized and rogue wireless access points
  • 2.2.4 2.2.4 Only necessary functionality enabled
  • 5.3.4 5.3.4 Anti-malware audit logs enabled and retained
  • 5.3.5 5.3.5 Users cannot disable or alter anti-malware
  • 5.2.1 5.2.1 Anti-malware deployed on all system components
  • 5.2.2 5.2.2 Anti-malware detects and handles all known malware
  • 5.3.1 5.3.1 Anti-malware kept current through automatic updates
  • 5.3.2 5.3.2 Periodic and real-time scans or continuous behavioural analysis
  • 5.3.3 5.3.3 Anti-malware covers removable electronic media
  • ASD37-01 Application control (Essential)
  • ASD37-05 Automated dynamic analysis of email and web content (Excellent)
  • ASD37-06 Email content filtering (Excellent)
  • ASD37-07 Web content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-15 User education (Limited)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-30 Endpoint detection and response (Very Good)

NIST SP 800-53 Rev 5 · 8 controls

CMMC 2.0 · 6 controls

ACSC Essential Eight · 5 controls

  • E8-APP-ML1 Application Control (ML1)
  • E8-APP-ML2 Application Control (ML2)
  • E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1)
  • E8-MACRO-ML3 Configure Microsoft Office Macro Settings (ML3)
  • E8-UAH-ML1 User Application Hardening - Maturity Level 1
  • NIST-CSF-DE.AE-06 Information on adverse events is provided to authorized staff and tools
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents

SOC 2 · 4 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies
  • ASBv3-ES-3 Ensure anti-malware software and signatures are updated
  • ES-1 Use Endpoint Detection and Response (EDR)
  • ES-2 Use modern anti-malware software

ISO 22301:2019 · 3 controls

  • 8.2.3 Risk assessment
  • 8.3.2 Identification of strategies and solutions
  • 8.4.4 Business continuity plans

ISO 27001:2022 · 3 controls

  • 8.19 Installation of software on operational systems
  • 8.23 Web filtering
  • 8.7 Protection against malware

ISO 27002:2022 · 3 controls

  • 8.19 Installation of software on operational systems
  • 8.23 Web filtering
  • 8.7 Protection against malware

NIST SP 800-171 Rev 3 · 3 controls

UK Cyber Essentials · 3 controls

  • CE-MP.1 Anti-Malware Software Deployed
  • CE-MP.2 Anti-Malware Signatures Updated
  • CE-MP.3 Anti-Malware Scans Files on Access and Web Pages

C5 (Germany) · 2 controls

  • C5-OPS-04 Protection Against Malware - Concept
  • C5-OPS-05 Protection Against Malware - Implementation

FedRAMP High · 2 controls

  • SI-3 Malicious Code Protection
  • SI-8 Spam Protection

FedRAMP Moderate · 2 controls

  • SI-3 Malicious Code Protection
  • SI-8 Spam Protection
  • CBPR-PR-32 Detection, prevention and response measures

APRA CPS 234 · 1 control

  • CPS234-30 Detection and Response Mechanisms
  • AUCDR-IS-5 Limit, prevent, detect and remove malware

ISO 27701:2019 · 1 control

  • 6.9.2 Protection from malware

NIST SP 800-172 · 1 control

  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Administrative

Query this from an agent

The graph holds this control, the 94 it maps to, and the evidence behind each claim, over MCP and REST.