5.2.2 The deployed anti-malware solution(s): • Detects all known types of malware. • Removes, blocks, or contains all known types of malware
The deployed anti-malware solution(s): • Detects all known types of malware. • Removes, blocks, or contains all known types of malware.
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
- Mapping of legal, regulatory, and contractual privacy obligations to PIMS controls · Policy repository / GRC workspace
First move
Common gaps auditors find
- Interested parties relevant to PII processing not enumerated
- Requirements of PII principals, regulators, and customers not captured in a single register
- No mapping from stakeholder expectations to specific PIMS controls
- Updates to legal and contractual privacy requirements not tracked
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet5.2.1 An anti-malware solution(s) is deployed on all system components, except for those system components identified in periodic evaluations per Requirement 5.2.3 that concludes the system components are not at risk from malware · 5.2.3 Any system components that are not at risk for malware are evaluated periodically to include the following: • A documented list of all system components not at risk for malware. • Identification and evaluation