# Malware protection policy

Source: https://aestech.com.au/policy-templates/#malware-protection-policy
Markdown URL: https://aestech.com.au/policy-templates/malware-protection-policy.md

Use for ISO 27001 A.8.7, SOC 2 Security, and PCI DSS requirement 5 anti-malware controls.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how the company prevents, detects and responds to malicious software, including viruses, ransomware, spyware and malicious scripts, so that systems and data are protected from compromise.

2. Scope
This policy applies to all company endpoints, servers, virtual machines, cloud workloads, email systems and web browsing, and to all employees and contractors who use company systems or access company data.

3. Policy statements
- Approved endpoint protection software must be installed, enabled and kept current on all workstations and servers that support it.
- Endpoint protection must include real-time scanning and, where available, behavioural detection and ransomware protection.
- Signature and detection engine updates must be applied automatically and at least daily.
- Users must not disable, bypass or uninstall malware protection, and administrative controls must prevent this on managed devices.
- Email must be filtered for malicious attachments, links and spoofing before delivery to users.
- Web filtering must block known malicious sites and unapproved high-risk file downloads where technically practical.
- Software may only be installed from approved sources, and execution of unauthorised software should be restricted on managed devices.
- Files received from external parties or downloaded from the internet must be scanned before use where scanning is not automatic.
- Systems that cannot run endpoint protection must be identified and protected with compensating controls approved by the [Security Lead].
- Confirmed or suspected malware infections must be treated as security events under the incident response policy.

4. Roles and responsibilities
- The [Security Lead] owns the malware protection programme, selects approved tooling and approves exceptions.
- IT deploys and maintains endpoint protection, email filtering and web filtering, and monitors coverage.
- System owners ensure their systems meet these requirements.
- All users report suspected infections, suspicious emails and unexpected system behaviour immediately through [reporting channel].

5. Procedures
- Deploy endpoint protection through central management and enrol every eligible device.
- Monitor the management console for coverage gaps, outdated agents and detections on a [daily or weekly] cadence.
- On detection, isolate the affected device from the network, preserve logs, remove the malware or reimage the device, and reset credentials used on it where compromise is possible.
- Verify that email and web filtering rules remain effective after major platform changes.
- Review devices without protection and record compensating controls or remediation.

6. Evidence and records
Keep endpoint protection coverage reports, update status, detection and quarantine logs, email filtering configuration and reports, incident tickets for infections, isolation and reimage records, and exception approvals.

7. Review cadence
This policy is reviewed at least annually and after significant malware incidents or changes to protection tooling.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md