Skip to contentSkip to content
Maintain a Vulnerability Management Programme
5

Protect All Systems and Networks from Malicious Software

Anti-malware solutions must be deployed on all systems commonly affected by malicious software, kept current, and configured for active protection. This requirement covers traditional antivirus, next-generation endpoint detection, and emerging threat vectors including phishing and social engineering.

Control Intent

Protect all system components in the CDE from all types of malicious software through deployment, maintenance, and active monitoring of anti-malware solutions, including periodic evaluations of components not typically targeted.

Common Failures

  • Anti-malware not deployed on all in-scope systems, particularly Linux servers assumed not to need it
  • Signature databases not updated regularly, leaving systems vulnerable to known threats
  • Anti-malware configured to allow user overrides without management authorisation controls
  • No anti-phishing mechanisms in place for email or web browsing
  • Failure to periodically re-evaluate whether systems considered low-risk still do not require anti-malware