INF-009 Malware and Endpoint Protection
Description
Managed endpoints and production workloads are protected by anti-malware or endpoint detection and response tooling with up-to-date signatures or behavioural detection. Software firewalls are configured on managed endpoints. Unauthorised or user-installed software on production systems is prevented or detected. Inbound email is filtered for spam and phishing, and the filter's detection content is updated automatically at the interval the supplier defines.
Rationale
Endpoint protection and host-based controls are the last line of defence against a compromised endpoint or malicious code running in production. Email belongs with them because it is the route most of that code arrives by, and the filter is the one detection surface whose value collapses fastest without current content: a campaign is usually days old, so a filter updated weekly by hand is filtering last week's attacks. Automatic updates are the requirement rather than a convenience.
Applicability (9 profiles)
Framework Mappings (24)
| TVM-02 | Malware and Malicious Instructions Protection Policy and Procedures | full |
| UEM-05 | Endpoint Management | full |
| UEM-09 | Anti-Malware Detection and Prevention | full |
| UEM-10 | Software Firewall | full |
| TVM-02 | Malware and Malicious Instructions Protection Policy and Procedures | full |
| UEM-05 | Endpoint Management | full |
| UEM-09 | Anti-Malware Detection and Prevention | full |
| UEM-10 | Software Firewall | full |
| HIPAA-164.308.a.5.ii.B | Protection from Malicious Software | partial |
| 8.1 | User endpoint devices | informative |
| 8.19 | Installation of software on operational systems | full |
| 8.7 | Protection against malware | full |
| NIS2-CIR-12.3 | Removable Media Policy | informative |
| NIS2-CIR-6.9 | Protection Against Malicious and Unauthorised Software | full |
| CM-11 | User-installed Software | partial |
| CM-7(2) | Least Functionality | Prevent Program Execution | partial |
| CM-7(5) | Least Functionality | Authorized Software — Allow-by-exception | partial |
| SC-18 | Mobile Code | informative |
| SC-44 | Detonation Chambers | informative |
| SC-7(12) | Boundary Protection | Host-based Protection | partial |
| SI-3 | Malicious Code Protection | full |
| SI-4(23) | System Monitoring | Host-based Devices | full |
| SI-8 | Spam Protection | partial |
| SI-8(2) | Spam Protection | Automatic Updates | full |
Evidence (3)
EDR or anti-malware management console report showing deployment coverage, signature/detection engine currency, and alert status across managed endpoints and production workloads.
Example: CrowdStrike Falcon, Microsoft Defender for Endpoint, or Sentinel One management console export showing agent deployment percentage, last signature update, and active alerts for production scope
Test: Export the EDR management console coverage report. Verify: (1) EDR or anti-malware agents are deployed on all managed endpoints and production workloads in scope; (2) signatures or detection models were updated within the vendor-defined maximum interval; (3) any endpoint with a gap in coverage has a documented remediation timeline; (4) host-based firewalls are shown as enabled on managed endpoints.
Software installation restriction policy configuration (e.g., allowlisting or MDM policy) preventing unauthorised software installation on production systems and managed endpoints.
Example: MDM (Jamf, Intune, or equivalent) software restriction policy configuration export or AWS Systems Manager Inventory report showing unapproved software detected on production instances
Test: Request the software restriction policy configuration export. Verify: (1) a policy is enforced that prevents or alerts on installation of unapproved software; (2) the policy covers all managed endpoints and production workloads; (3) any software installation alerts from the last 90 days have been reviewed and actioned.
Email filtering configuration showing spam and phishing detection in force across the organisation's inbound mail and the automatic update setting for its detection content.
Example: Mail security policy export, all accepted domains, 2026-08-21
Test: Export the email filtering configuration. Verify: (1) filtering is applied to every inbound mail domain the organisation accepts mail on, including aliases and parked domains, (2) the detection content's last update timestamp falls within the interval the supplier defines, (3) updates are applied automatically rather than by a scheduled manual task, (4) the filter is in enforcing mode rather than logging only, (5) an exclusion or allowlist entry in force carries a recorded justification and an expiry.
Questions (2)
Are managed endpoints and production workloads protected by anti-malware or endpoint detection and response tooling?
EDR deployment should cover all managed endpoints and, where applicable, production compute workloads. Behavioural detection (EDR) is preferred over signature-only anti-malware.
Which endpoint and workload protection tooling is deployed across production systems and managed endpoints?
Options run from the strongest coverage to the weakest. A modern detection and response agent across all managed endpoints plus host-based firewall enforcement is the minimum for a service provider. Email filtering belongs here because it is the route most malicious code arrives by, and its value collapses fastest without current detection content. Name capabilities rather than products when recording what is deployed.