A process must be in place for updating malware protection also in systems that are not connected to a public network. Updates to malware signatures may be arranged, for example, by using a managed and secured update server, with its signature database kept up to date by manually transferring the signatures from a separate internet-connected system (e. g. 1-3 times per week), or by importing the signatures through an approved gateway solution. The adequacy of the update frequency must be assessed in relation to the characteristics of the specific environment in the risk assessment, particularly taking into account the frequency of other data transfers in the environment.
There must also be a predefined procedure to ensure the integrity of updates (e. g. source, checksums, signatures).