SC-35 External Malicious Code Identification. Include system components that proactively seek to identify network-based malicious code or malicious websites
External Malicious Code Identification. Include system components that proactively seek to identify network-based malicious code or malicious websites.
system holds itEvidence a system already holds
- Configuration of those components, including the sources and frequency of proactive checking · Cloud console / configuration management
periodic reviewEvidence produced at each review
- Records of malicious code or sites identified during the period and the action taken · Document repository
- Evidence the components operate proactively rather than only inspecting user initiated traffic · Document repository
governing documentDocuments that govern the control
- Identification of the system components deployed to proactively seek network based malicious code or malicious websites · Policy repository / GRC workspace
- Isolation of the seeking component so its own exposure does not become a compromise path · Document repository
First move
Common gaps auditors find
- Capability limited to inspecting traffic users generate, with no proactive seeking, which is the distinguishing requirement
- Identified malicious sites recorded but never fed into the blocking mechanism that would act on them
- The seeking component runs on the production network, so its deliberate contact with malicious content endangers the estate
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetSC-34 Non-modifiable Executable Programs. For [organization-defined] , load and execute: The operating environment from hardware-enforced, read-only media; and The following applications from hardware-enforced, read-only media: [organization-defined] · SC-36 Distributed Processing and Storage. Distribute the following processing and storage components across multiple [organization-defined]: [organization-defined]