A.8.7 Protection against malware
Implement malware protection backed by user awareness.
12
artefacts
2
held by a system
4
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Phishing Simulation Results · Endpoint management (MDM / EDR)
- Malware Incident Response Log · Endpoint management (MDM / EDR)
periodic reviewEvidence produced at each review
- Configuration Baseline Screenshots · Endpoint management (MDM / EDR)
- Patch Management Records · Vulnerability scanner / patch tooling
- Attendance Records for malware awareness sessions · Endpoint management (MDM / EDR)
- Post-incident Review Minutes · Endpoint management (MDM / EDR)
governing documentDocuments that govern the control
- Malware Protection Policy document · Policy repository / GRC workspace
- Approved Anti-Malware Software List · Policy repository / GRC workspace
- Policy Change Log · Policy repository / GRC workspace
- Endpoint Protection Deployment Report · Policy repository / GRC workspace
- Security Awareness Training Materials · HR system / LMS
- Root Cause Analysis Reports · Policy repository / GRC workspace
First move
Mostly documents and reviews. Pull the 2 system-held artefacts from your Endpoint management (MDM / EDR) on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Outdated malware signatures not regularly updated
- Training limited to annual sessions
- No documented process for malware incident escalation
- Inconsistent endpoint protection across device types
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.8.6 Capacity management · A.8.8 Management of technical vulnerabilities