UEM-09 Anti-Malware Detection and Prevention
Deploy anti-malware technology on managed endpoints configured to both detect and actively block malicious code, not merely report it.
4
artefacts
1
held by a system
1
at each review
moderate
to go live
Endpoint management (MDM / EDR)
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Configuration showing detection and prevention both enabled · Endpoint management (MDM / EDR)
periodic reviewEvidence produced at each review
- Records of detections and their handling · Endpoint management (MDM / EDR)
governing documentDocuments that govern the control
- Anti-malware deployment coverage against the endpoint inventory · Policy repository / GRC workspace
- Health reporting, such as devices with disabled or stale protection · Policy repository / GRC workspace
First move
Start with the 1 of 4 artefacts that already live in a system (Endpoint management (MDM / EDR)); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Detection enabled with prevention disabled to avoid disruption
- Coverage gaps on servers or developer machines
- Stale or disabled agents unnoticed because health is not monitored
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet