SOC 2
CC - Common Criteria (Security)

SOC 2 SOC2-CC6.8: CC6.8 Preventing and detecting unauthorised or malicious software

Controls prevent, or detect and respond to, the introduction of unauthorised or malicious software. Points of focus: only authorised people can install applications and software; changes to software and configuration that may signal malicious code are detected; software is implemented through a management-defined change process; utility software able to bypass normal operating or security procedures is restricted to authorised people and its use monitored (added in 2022); anti-malware on servers and endpoints is configured, kept current and used to remove what it detects; and assets received from outside or returned to the organisation are scanned and cleaned before joining the network.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 246 controls across 33 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 29 controls

  • CIS-1.2 Address Unauthorized Assets
  • CIS-10.1 Deploy and Maintain Anti-Malware Software
  • CIS-10.2 Configure Automatic Anti-Malware Signature Updates
  • CIS-10.3 Disable Autorun and Autoplay for Removable Media
  • CIS-10.4 Configure Automatic Anti-Malware Scanning of Removable Media
  • CIS-10.5 Enable Anti-Exploitation Features
  • CIS-10.6 Centrally Manage Anti-Malware Software
  • CIS-10.7 Use Behavior-Based Anti-Malware Software
  • CIS-13.2 Deploy a Host-Based Intrusion Detection Solution
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution
  • CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.3 Address Unauthorized Software
  • CIS-2.4 Utilize Automated Software Inventory Tools
  • CIS-2.5 Allowlist Authorized Software
  • CIS-2.6 Allowlist Authorized Libraries
  • CIS-2.7 Allowlist Authorized Scripts
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.7 Remediate Detected Vulnerabilities
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
  • CIS-9.2 Use DNS Filtering Services
  • CIS-9.3 Maintain and Enforce Network-Based URL Filters
  • CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions
  • CIS-9.6 Block Unnecessary File Types
  • CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections

NIST SP 800-53 Rev 5 · 29 controls

PCI DSS 4.0 · 25 controls

  • 1.5.1 1.5.1 Security controls on dual-connected devices
  • 10.3.4 10.3.4 File integrity monitoring on audit logs
  • 11.2.1 11.2.1 Detect authorized and rogue wireless access points
  • 11.2.2 11.2.2 Inventory of authorized wireless access points
  • 11.3.1.2 11.3.1.2 Authenticated internal vulnerability scanning
  • 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic
  • 11.5.1.1 11.5.1.1 Service providers detect covert malware channels
  • 11.5.2 11.5.2 Change detection on critical files
  • 11.6.1 11.6.1 Payment page tamper detection
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.2.4 2.2.4 Only necessary functionality enabled
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 5.3.4 5.3.4 Anti-malware audit logs enabled and retained
  • 5.3.5 5.3.5 Users cannot disable or alter anti-malware
  • 5.4.1 5.4.1 Mechanisms detect and protect against phishing
  • 6.2.4 6.2.4 Engineering techniques against common software attacks
  • 9.5.1 9.5.1 Protection of POI devices from tampering
  • 5.2.1 5.2.1 Anti-malware deployed on all system components
  • 5.2.2 5.2.2 Anti-malware detects and handles all known malware
  • 5.2.3 5.2.3 Periodic evaluation of components not at risk from malware
  • 5.3.1 5.3.1 Anti-malware kept current through automatic updates
  • 5.3.2 5.3.2 Periodic and real-time scans or continuous behavioural analysis
  • 5.3.3 5.3.3 Anti-malware covers removable electronic media
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.4.3 6.4.3 Payment page script management

FedRAMP High · 23 controls

  • AC-20(2) Portable Storage Devices Restricted Use
  • CM-10 Software Usage Restrictions
  • CM-11 User-Installed Software
  • CM-7 Least Functionality
  • CM-7(2) Prevent Program Execution
  • CM-7(5) Authorized Software Allow-by-Exception
  • CM-8(3) Automated Unauthorized Component Detection
  • MA-3 Maintenance Tools (MA-3)
  • MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1))
  • MA-3(2) Maintenance Tools | Inspect Media (MA-3(2))
  • SA-1 Policy and Procedures
  • SC-18 Mobile Code
  • SC-39 Process Isolation
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SI-16 Memory Protection
  • SI-3 Malicious Code Protection
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(1) Integrity Checks
  • SI-7(7) Integration of Detection and Response
  • SI-8 Spam Protection
  • SI-8(2) Spam Protection | Automatic Updates (SI-8(2))
  • SR-11 Component Authenticity (SR-11)

FedRAMP Moderate · 23 controls

  • AC-20(2) Portable Storage Devices Restricted Use
  • CM-10 Software Usage Restrictions
  • CM-11 User-Installed Software
  • CM-7 Least Functionality
  • CM-7(2) Prevent Program Execution
  • CM-7(5) Authorized Software Allow-by-Exception
  • CM-8(3) Automated Unauthorized Component Detection
  • MA-3 Maintenance Tools (MA-3)
  • MA-3(1) Maintenance Tools | Inspect Tools (MA-3(1))
  • MA-3(2) Maintenance Tools | Inspect Media (MA-3(2))
  • SA-1 Policy and Procedures
  • SC-18 Mobile Code
  • SC-39 Process Isolation
  • SC-7(12) Boundary Protection | Host-based Protection (SC-7(12))
  • SI-16 Memory Protection
  • SI-3 Malicious Code Protection
  • SI-4(4) Inbound and Outbound Communications Traffic
  • SI-7 Software, Firmware, and Information Integrity
  • SI-7(1) Integrity Checks
  • SI-7(7) Integration of Detection and Response
  • SI-8 Spam Protection
  • SI-8(2) Spam Protection | Automatic Updates (SI-8(2))
  • SR-11 Component Authenticity (SR-11)

CMMC 2.0 · 16 controls

ISO 27701:2019 · 10 controls

  • 6.10 Communications security
  • 6.11 Systems acquisition, development and maintenance
  • 6.11.2 Security in development and support processes
  • 6.3.2 Mobile devices and teleworking
  • 6.6.2 User access management
  • 6.9 Operations security
  • 6.9.2 Protection from malware
  • 6.9.4 Logging and monitoring
  • 6.9.5 Control of operational software
  • 6.9.6 Technical vulnerability management

ISO 27002:2022 · 9 controls

  • 8.1 User endpoint devices
  • 8.12 Data leakage prevention
  • 8.17 Clock synchronization
  • 8.19 Installation of software on operational systems
  • 8.23 Web filtering
  • 8.26 Application security requirements
  • 8.28 Secure coding
  • 8.7 Protection against malware
  • 8.8 Management of technical vulnerabilities

HIPAA Security Rule · 7 controls

NIST SP 800-66 Rev 2 · 7 controls

ISO 27001:2022 · 6 controls

  • 8.1 User end point devices
  • 8.18 Use of privileged utility programs
  • 8.19 Installation of software on operational systems
  • 8.23 Web filtering
  • 8.7 Protection against malware
  • 8.8 Management of technical vulnerabilities
  • NIST-CSF-DE.CM-09 Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.DS-11 Backups of data are created, protected, maintained, and tested
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
  • NIST-CSF-RS.MI-02 Incidents are eradicated
  • ASD37-01 Application control (Essential)
  • ASD37-03 Configure Microsoft Office macro settings (Essential)
  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASBv3-AM-5 Use only approved applications in virtual machine
  • ASBv3-ES-3 Ensure anti-malware software and signatures are updated
  • ASBv3-GS-9 Define and implement endpoint security strategy
  • ES-1 Use Endpoint Detection and Response (EDR)
  • ES-2 Use modern anti-malware software

ACSC Essential Eight · 4 controls

  • E8-APP-ML2 Application Control (ML2)
  • E8-MACRO-ML1 Configure Microsoft Office Macro Settings (ML1)
  • E8-MACRO-ML3 Configure Microsoft Office Macro Settings (ML3)
  • E8-UAH-ML1 User Application Hardening - Maturity Level 1

NIST SP 800-161 Rev 1 · 4 controls

NIST SP 800-171 Rev 3 · 4 controls

UK Cyber Essentials · 4 controls

  • CE-MP.1 Anti-Malware Software Deployed
  • CE-MP.2 Anti-Malware Signatures Updated
  • CE-MP.3 Anti-Malware Scans Files on Access and Web Pages
  • CE-MP.4 Application Allowlisting (Alternative)

C5 (Germany) · 3 controls

  • C5-OPS-04 Protection Against Malware - Concept
  • C5-OPS-05 Protection Against Malware - Implementation
  • C5-PSS-11 Images for Virtual Machines and Containers

NIST SP 800-172 · 3 controls

  • 3.14.1e Verify Integrity of Security Critical Software and Firmware
  • 3.4.1e Authoritative Source for Software and Firmware
  • 3.4.2e Automated Detection and Remediation of Unauthorized Software

NIST SP 800-218 · 3 controls

DORA · 2 controls

AICPA SOC 3 · 1 control

  • SOC3-LOGICAL-ACCESS Logical Access

APPI · 1 control

APRA CPS 234 · 1 control

  • CPS234-21 Implementation of Information Security Controls
  • AUCDR-IS-5 Limit, prevent, detect and remove malware

EU AI Act · 1 control

ISO/IEC 42001:2023 · 1 control

  • A.6.2.8 AI system recording of event logs

NIS2 Directive · 1 control

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CC - Common Criteria (Security)

You are reading one control. How much of SOC 2 have you already done?

SOC 2 SOC2-CC6.8 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of SOC 2 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 49 of 61 SOC 2 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 193 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 246 it maps to, and the evidence behind each claim, over MCP and REST.