ISO 27001 Annex : A.12.2 Protection from Malware
ISO 27001 Annex : A.12.2 Protection from Malware It’s objective is ensuring that malware protection is provided to information and information processing facilities. A.12.2.1 Controls Against Malware Control- In combination with appropriate user awareness, the detection, prevention, and recovery controls to protect against malware should be implemented. Implementation guidance Malware protection should be supported by malware detection and repair software, awareness of the safety of information, and adequate system access and management reviews on changes. The guidance should be considered as follows: a create formal policy barring the use of unauthorized software; Implementation of controls preventing or detecting the use of unauthorized software; Implement controls which avoid or detect the use of malicious websites known or suspected (e.g. blacklisting); Create a structured risk management policy, which indicates wha...