Requirement 5: Protect all systems and networks from malicious software
Malware is a primary breach vector. Components must be protected, and protections kept current and active.
Sub-requirements
5.1
Processes and mechanisms are defined and understood
2 defined requirementsDocument anti-malware policy and ownership.
View defined requirements →5.2
Malware is prevented, or detected and addressed
4 defined requirementsDeploy anti-malware on systems commonly affected, and evaluate periodically for those not.
View defined requirements →5.3
Anti-malware mechanisms are active and monitored
6 defined requirementsKeep engines current, run periodic scans, and prevent users from disabling them.
View defined requirements →5.4
Anti-phishing mechanisms protect users
1 defined requirementDeploy technical anti-phishing controls (e.g. email filtering) alongside awareness training.
View defined requirements →Tips
- ›Centrally manage endpoint protection so you can prove it is active everywhere.
- ›Combine email filtering with phishing simulations for requirement 5.4.
Evidence to keep
- ✓Anti-malware deployment report
- ✓Scan/update logs
- ✓Email filtering configuration
Example
Managed EDR runs on all endpoints and servers, auto-updates, cannot be disabled by users, and reports status to a central console; email gateway filters phishing.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Malware protection policyUse for ISO 27001 A.8.7, SOC 2 Security, and PCI DSS requirement 5 anti-malware controls.Security awareness and training policyUse for ISO 27001 A.6.3, SOC 2 Security awareness criteria, and PCI DSS requirement 12.6 training obligations.Acceptable use policyUse for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness.Incident response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling.
Open the control-to-policy map