Protection against malware
Purpose
Protect information and related assets against malware, backed by user awareness.
How to meet this control
In short: Implement malware protection supported by user awareness.
- Step 01Deploy a next-generation antivirus or EDR agent (Microsoft Defender, CrowdStrike, SentinelOne) to every endpoint and server with central reporting
- Step 02Enable real-time scanning of files, email attachments, downloads and removable media, and keep signatures and engines auto-updating
- Step 03Apply application control or allowlisting on high-value hosts so only approved executables run
- Step 04Layer email security (Microsoft Defender for Office 365, Proofpoint, Mimecast) to detonate attachments and rewrite malicious links
- Step 05Combine malware defence with phishing awareness training and simulations so users are an active control
- Step 06Keep offline or immutable backups so a ransomware event can be recovered without paying
Tip: Endpoint protection on all devices plus awareness training.
What ISO 27002 says to cover
Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.
- ›Use detection and repair tools alongside awareness, access control and change management
- ›Prevent or detect unauthorised software with application allowlisting and block malicious websites
- ›Reduce exploitable vulnerabilities and validate that systems contain only approved files
- ›Install and regularly update anti-malware and scan networks, email, attachments and media
- ›Place detection tools using defence-in-depth, accounting for evasion techniques
- ›Guard against malware introduced during maintenance and isolate high-consequence environments
- ›Prepare continuity and recovery plans, including online and offline backups
- ›Train users to recognise malware and gather malware intelligence from reputable sources
Audit evidence to keep
- - EDR or antivirus console showing fleet coverage and definition currency
- - Configuration of real-time scanning and removable media policy
- - Email security gateway policy and a sample quarantined or detonated threat
- - Phishing simulation results and awareness training completion records
- - Evidence of immutable or offline backup protecting against ransomware
Common mistakes
- - Writing a policy but not operating the process
- - Keeping evidence in personal folders where auditors cannot trace it
- - Letting exceptions stay open with no owner or expiry date
Owner, cadence, and proof
Assign one accountable owner for A.8.7. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.