Posts

Showing posts with the label System Access and Management Reviews

ISO 27001 Annex : A.12.2 Protection from Malware

Image
  ISO 27001 Annex : A.12.2 Protection from Malware  It’s objective is  ensuring that malware protection is provided to information and information processing facilities. A.12.2.1  Controls Against Malware Control-  In combination with appropriate user awareness, the detection, prevention, and recovery controls to protect against malware should be implemented. Implementation guidance Malware protection should be supported by malware detection and repair software, awareness of the safety of information, and adequate system access and  management reviews  on changes. The guidance should be considered as follows: a create formal policy barring the use of unauthorized software;   Implementation of controls preventing or detecting the use of unauthorized software; Implement controls which avoid or detect the use of malicious websites known or suspected (e.g. blacklisting); Create a structured  risk management   policy, which indicates wha...