Skip to content

SI-3: Malicious Code Protection

An OSCAL Control

Statement

    • a.

      Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code;

    • b.

      Automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy and procedures;

    • c.

      Configure malicious code protection mechanisms to:

      • 1.

        Perform periodic scans of the system and real-time scans of files from external sources at as the files are downloaded, opened, or executed in accordance with organizational policy; and

      • 2.

        ; and send alert to in response to malicious code detection; and

    • d.

      Address the receipt of false positives during malicious code detection and eradication and the resulting potential impact on the availability of the system.