PlumbTrackLive demoGRC Risk System

← internal audit

Audit — SI-3 — Malicious Code Protection

Framework: NIST SP 800-53 Rev.5 SI-3 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Examine the anti-malware deployment/coverage report and confirm centrally managed endpoint protection is installed, running, and reporting on all in-scope endpoints and servers (CIS Control 10 Malware Defenses).
Examine Examine the management console to confirm malicious-code definitions and detection engines are configured to update automatically and are current within the policy-defined interval.
Examine Examine endpoint policy configuration to confirm real-time (on-access) scanning is enabled and scheduled periodic full scans are configured.
Examine Examine the configured detection response and verify the tool is set to automatically block/quarantine malicious code and generate an alert to administrators on detection.
Test Deploy a benign EICAR test file (or equivalent) to a sample endpoint and observe that it is detected, quarantined/blocked, and an alert is generated.
Interview How does the security operations team triage malware alerts, handle false positives, and confirm remediation of infected hosts?
Examine Examine coverage at network entry/exit points (email gateway, web/proxy) and confirm anti-exploitation or behavior-based detection is enabled for content the organization cannot inspect with signatures alone (CIS Control 10.7).