Anti-virus, -spyware, and other -malware programs shall be installed and updated.
Guidance
- Malware includes viruses, spyware, and ransomware and should be countered by installing, using,
and regularly updating anti-virus and anti-spyware software on every device used in company’s
business (including computers, smart phones, tablets, and servers).
- Anti-virus and anti-spyware software should automatically check for updates in “real-time” or at least
daily followed by system scanning as appropriate.
- It should be considered to provide the same malicious code protection mechanisms for home
computers (e.g. teleworking) or personal devices that are used for professional work (BYOD).
The organization shall set up a system to detect false positives while detecting and eradicating malicious code.
Centrally select and install malware detection and repair programs and update them regularly for preventive or regular scanning of computers and media.
Programs should check at least the following:
Malware protection systems automatically check for and install updates at desired intervals and also run the desired scans at the selected frequency without needed user actions.
The organization must identify the types of websites that staff should and should not have access to.
The organization must consider blocking access to the following types of sites (either automatically or by other means):
The data systems (and their content) that support critical business processes are regularly reviewed to locate malware. All unauthorized files and changes will be formally investigated.
We always use malware systems from multiple vendors to improve the likelihood of detecting malware.