DE.CM-4.1: Anti-virus, -spyware, and other -malware programs shall be installed and updated.
Malware includes viruses, spyware, and ransomware and should be countered by installing, using, and regularly updating anti-virus and anti-spyware software on every device used in company’s business (including computers, smart phones, tablets, and servers).
Anti-virus and anti-spyware software should automatically check for updates in “real-time” or at least daily followed by system scanning as appropriate.
It should be considered to provide the same malicious code protection mechanisms for home computers (e.g. teleworking) or personal devices that are used for professional work (BYOD).
Documentation Maturity
Implementation Maturity
Description
Anti-virus, -spyware, and other -malware programs shall be installed and updated.
DE.CM-4.2
DE.CM-4.2: The organisation shall set up a system to detect false positives while detecting and eradicating malicious code.
Documentation Maturity
Implementation Maturity
Description
The organisation shall set up a system to detect false positives while detecting and eradicating malicious code.