Frameworks / SOC 2 / SOC2-CC6.8 SOC 2
CC - Common Criteria (Security)
SOC 2 SOC2-CC6.8: CC6.8 Preventing and detecting unauthorised or malicious software Controls prevent, or detect and respond to, the introduction of unauthorised or malicious software. Points of focus: only authorised people can install applications and software; changes to software and configuration that may signal malicious code are detected; software is implemented through a management-defined change process; utility software able to bypass normal operating or security procedures is restricted to authorised people and its use monitored (added in 2022); anti-malware on servers and endpoints is configured, kept current and used to remove what it detects; and assets received from outside or returned to the organisation are scanned and cleaned before joining the network.
Maintained by Gerard Blokdyk · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 246 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-1.2 Address Unauthorized Assets CIS-10.1 Deploy and Maintain Anti-Malware Software CIS-10.2 Configure Automatic Anti-Malware Signature Updates CIS-10.3 Disable Autorun and Autoplay for Removable Media CIS-10.4 Configure Automatic Anti-Malware Scanning of Removable Media CIS-10.5 Enable Anti-Exploitation Features CIS-10.6 Centrally Manage Anti-Malware Software CIS-10.7 Use Behavior-Based Anti-Malware Software CIS-13.2 Deploy a Host-Based Intrusion Detection Solution CIS-13.5 Manage Access Control for Remote Assets CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure CIS-2.1 Establish and Maintain a Software Inventory CIS-2.2 Ensure Authorized Software is Currently Supported CIS-2.3 Address Unauthorized Software CIS-2.4 Utilize Automated Software Inventory Tools CIS-2.5 Allowlist Authorized Software CIS-2.6 Allowlist Authorized Libraries CIS-2.7 Allowlist Authorized Scripts CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets CIS-7.4 Perform Automated Application Patch Management CIS-7.7 Remediate Detected Vulnerabilities CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients CIS-9.2 Use DNS Filtering Services CIS-9.3 Maintain and Enforce Network-Based URL Filters CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions CIS-9.6 Block Unnecessary File Types CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections 1.5.1 1.5.1 Security controls on dual-connected devices 10.3.4 10.3.4 File integrity monitoring on audit logs 11.2.1 11.2.1 Detect authorized and rogue wireless access points 11.2.2 11.2.2 Inventory of authorized wireless access points 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic 11.5.1.1 11.5.1.1 Service providers detect covert malware channels 11.5.2 11.5.2 Change detection on critical files 11.6.1 11.6.1 Payment page tamper detection 12.6.1 12.6.1 Formal security awareness program 2.2.4 2.2.4 Only necessary functionality enabled 3.4.2 3.4.2 Remote access blocks copying or relocating PAN 5.3.4 5.3.4 Anti-malware audit logs enabled and retained 5.3.5 5.3.5 Users cannot disable or alter anti-malware 5.4.1 5.4.1 Mechanisms detect and protect against phishing 6.2.4 6.2.4 Engineering techniques against common software attacks 9.5.1 9.5.1 Protection of POI devices from tampering 5.2.1 5.2.1 Anti-malware deployed on all system components 5.2.2 5.2.2 Anti-malware detects and handles all known malware 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware 5.3.1 5.3.1 Anti-malware kept current through automatic updates 5.3.2 5.3.2 Periodic and real-time scans or continuous behavioural analysis 5.3.3 5.3.3 Anti-malware covers removable electronic media 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.4.3 6.4.3 Payment page script management AC-20(2) Portable Storage Devices Restricted Use CM-10 Software Usage Restrictions CM-11 User-Installed Software CM-7 Least Functionality CM-7(2) Prevent Program Execution CM-7(5) Authorized Software Allow-by-Exception CM-8(3) Automated Unauthorized Component Detection MA-3 Maintenance Tools (MA-3) MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1)) MA-3(2) Maintenance Tools | Inspect Media (MA-3(2)) SA-1 Policy and Procedures SC-18 Mobile Code SC-39 Process Isolation SC-7(12) Boundary Protection | Host-based Protection (SC-7(12)) SI-16 Memory Protection SI-3 Malicious Code Protection SI-4(4) Inbound and Outbound Communications Traffic SI-7 Software, Firmware, and Information Integrity SI-7(1) Integrity Checks SI-7(7) Integration of Detection and Response SI-8 Spam Protection SI-8(2) Spam Protection | Automatic Updates (SI-8(2)) SR-11 Component Authenticity (SR-11) AC-20(2) Portable Storage Devices Restricted Use CM-10 Software Usage Restrictions CM-11 User-Installed Software CM-7 Least Functionality CM-7(2) Prevent Program Execution CM-7(5) Authorized Software Allow-by-Exception CM-8(3) Automated Unauthorized Component Detection MA-3 Maintenance Tools (MA-3) MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1)) MA-3(2) Maintenance Tools | Inspect Media (MA-3(2)) SA-1 Policy and Procedures SC-18 Mobile Code SC-39 Process Isolation SC-7(12) Boundary Protection | Host-based Protection (SC-7(12)) SI-16 Memory Protection SI-3 Malicious Code Protection SI-4(4) Inbound and Outbound Communications Traffic SI-7 Software, Firmware, and Information Integrity SI-7(1) Integrity Checks SI-7(7) Integration of Detection and Response SI-8 Spam Protection SI-8(2) Spam Protection | Automatic Updates (SI-8(2)) SR-11 Component Authenticity (SR-11) 6.10 Communications security 6.11 Systems acquisition, development and maintenance 6.11.2 Security in development and support processes 6.3.2 Mobile devices and teleworking 6.6.2 User access management 6.9 Operations security 6.9.2 Protection from malware 6.9.4 Logging and monitoring 6.9.5 Control of operational software 6.9.6 Technical vulnerability management 8.1 User endpoint devices 8.12 Data leakage prevention 8.17 Clock synchronization 8.19 Installation of software on operational systems 8.23 Web filtering 8.26 Application security requirements 8.28 Secure coding 8.7 Protection against malware 8.8 Management of technical vulnerabilities 8.1 User end point devices 8.18 Use of privileged utility programs 8.19 Installation of software on operational systems 8.23 Web filtering 8.7 Protection against malware 8.8 Management of technical vulnerabilities NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle NIST-CSF-RS.MI-02 Incidents are eradicated ASD37-01 Application control (Essential) ASD37-03 Configure Microsoft Office macro settings (Essential) ASD37-06 Email content filtering (Excellent) ASD37-12 Antivirus software with heuristics (Very Good) ASD37-16 Antivirus software with signatures (Limited) ASBv3-AM-5 Use only approved applications in virtual machine ASBv3-ES-3 Ensure anti-malware software and signatures are updated ASBv3-GS-9 Define and implement endpoint security strategy ES-1 Use Endpoint Detection and Response (EDR) ES-2 Use modern anti-malware software E8-APP-ML2 Application Control (ML2) E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1) E8-MACRO-ML3 Configure Microsoft Office Macro Settings (ML3) E8-UAH-ML1 User Application Hardening - Maturity Level 1 CE-MP.1 Anti-Malware Software Deployed CE-MP.2 Anti-Malware Signatures Updated CE-MP.3 Anti-Malware Scans Files on Access and Web Pages CE-MP.4 Application Allowlisting (Alternative) C5-OPS-04 Protection Against Malware - Concept C5-OPS-05 Protection Against Malware - Implementation C5-PSS-11 Images for Virtual Machines and Containers 3.14.1e Verify Integrity of Security Critical Software and Firmware 3.4.1e Authoritative Source for Software and Firmware 3.4.2e Automated Detection and Remediation of Unauthorized Software SOC3-LOGICAL-ACCESS Logical Access CPS234-21 Implementation of Information Security Controls AUCDR-IS-5 Limit, prevent, detect and remove malware A.6.2.8 AI system recording of event logs Art.21.2.g Basic cyber hygiene practices and cybersecurity training Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in CC - Common Criteria (Security) You are reading one control. How much of SOC 2 have you already done? SOC 2 SOC2-CC6.8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 246 it maps to, and the evidence behind each claim, over MCP and REST.