ISO 27001 Protection Against Malware Explained – Annex A 8.7

Stuart Barker -271

ISO 27001 Annex A 8.7 Protection Against Malware involves a documented strategy to detect and prevent malicious code. Organisations should integrate these procedures into existing tools like SharePoint. This control ensures staff manage malware risks through daily operational tasks. It excludes reliance on external software interfaces without internal oversight.

Key Takeaways

  • Establish Formal Anti-Malware Policies: Draft and maintain clear procedures to detect, prevent, and respond to malicious software across all business systems.
  • Deploy Automated Detection and Prevention Tools: Use central security tools to scan files, email attachments, and downloads continuously for potential threats.
  • Restrict Unauthorised Software Installation: Block employees from downloading or running unapproved software to prevent untrusted code from entering network systems.
  • Enforce Centralised Patch Management: Keep operating systems, applications, and firmware updated to fix known security gaps before attackers exploit them.
  • Maintain Daily Operational Oversight: Ensure internal security teams review alert logs and malware reports daily rather than relying solely on automated systems.
  • Conduct Staff Security Awareness Training: Educate employees on phishing risks, suspicious attachments, and safe web browsing habits to stop malware infections early.
  • Isolate Infected Systems Quickly: Establish clear incident response steps to disconnect compromised devices from the network immediately and stop threats from spreading.
  • Perform Regular System Backups: Store offline or isolated backups of critical business data to enable fast system recovery in the event of a malware attack.

How to Implement ISO 27001 Annex A 8.7

  • Draft Clear Anti-Malware Policies: Publish official rules and operational procedures in central document stores to guide malware prevention and detection.
  • Enforce Software Approval Workflows: Require formal review and managerial sign-off before allowing any new software installations on business devices.
  • Automate Security Signature Updates: Configure malware detection tools to update virus definitions and threat intelligence feeds automatically across all endpoints.
  • Link Threat Alerts to Review Tickets: Connect automated security scan alerts to operational task systems to ensure prompt investigation by internal security staff.
  • Conduct Regular System Scans: Schedule routine automated scans across all network drives, servers, and user workstations to catch hidden threats early.
  • Review Security Configurations Periodically: Document regular checks of system security settings and firewall rules in internal knowledge bases to prevent drift.
  • Track Malware Trends in Leadership Meetings: Include malware detection metrics and incident summaries in regular management reviews to drive continuous improvement.
  • Restrict User Administrative Privileges: Limit local administrator access on user devices to prevent unauthorized execution of malicious files and software.
  • Train Staff on Phishing and Web Safety: Educate employees on common malware entry points, including suspicious email links, malicious downloads, and removable media.

How to Audit ISO 27001 Annex A 8.7

  • Inspect Anti-Malware Policies: Review documented standards to verify clear rules exist for malware protection, system scanning, definition updates, and software restrictions.
  • Verify Device Protection Coverage: Sample user laptops, servers, and virtual systems to confirm active anti-malware software is running and connected to central management.
  • Audit Central Updates and Threat Definitions: Check security consoles to confirm threat definitions and detection engines update automatically across all active devices.
  • Check Web and Email Filtering Controls: Inspect gateway settings to confirm automated scanning blocks malicious attachments, harmful links, and suspicious web downloads.
  • Verify User Access Rights and Software Controls: Review system permissions to confirm non-administrative users cannot install or run unauthorized software applications.
  • Review External Media Restrictions: Audit device control rules to verify external storage drives are blocked, set to read-only, or scanned automatically upon insertion.
  • Inspect Malware Incident Logs: Sample recent malware alerts to verify affected systems were isolated quickly and security teams followed response procedures.
  • Verify Employee Training Records: Check training logs to confirm staff complete regular awareness modules on spotting phishing emails, bad links, and suspicious files.
  • Audit System Backup Isolation Controls: Confirm that system backups are isolated or kept offline to prevent malware from corrupting saved recovery files.
  • Review Regular Security Audit Logs: Sample internal audit records to confirm ongoing verification of malware controls and endpoint health across the business.

Audit Evidence Checklist

  • Malware Protection Policy and Standards: Present a version-controlled anti-malware policy stored in central document repositories showing management approval sign-offs.
  • Security Alert Investigation Logs: Provide ticket histories and investigation logs documenting the review, containment, and resolution of security alerts.
  • Malware Review Meeting Minutes: Share regular management review records and meeting notes detailing discussions on malware threat trends and incident logs.
  • Staff Awareness Training Records: Supply employee training completion logs proving staff completed mandatory anti-malware and phishing awareness modules.
  • Central Security Configuration Evidence: Provide documented screenshots or exported files showing central security console settings, scan schedules, and update rules.
  • Software Request Approval Logs: Produce formal approval tickets proving software installation requests undergo security checks prior to deployment.
  • Data Backup and Recovery Verification Logs: Supply backup reports proving critical data is backed up regularly and isolated from network malware threats.

What to Teach Employees

  • Recognise Common Malware Threats: Train employees to spot suspicious email attachments, phishing links, deceptive update prompts, and unsafe websites.
  • Keep Security Software Active: Teach staff that endpoint anti-malware tools must stay turned on at all times and never be disabled.
  • Use Only Approved Software: Instruct users to request software through official channels and avoid downloading unapproved tools from external sites.
  • Follow Safe External Device Rules: Teach employees to scan USB drives before opening files and follow company rules on personal storage devices.
  • Report Odd System Behaviour Quickly: Show staff how to report warning signs such as sudden slow performance, pop-up alerts, or locked files right away.
  • Avoid Downloads from Unknown Sources: Train employees to verify file origins before opening downloaded files, scripts, or macro-enabled documents.
  • Understand Automatic Isolation Rules: Inform staff that devices may automatically disconnect from the network if security systems detect a severe threat.
  • Restart Promptly for Security Updates: Teach employees to restart their devices promptly when prompted so critical security updates can install.
  • Locate Master Security Guidelines: Show staff where to find official malware protection policies, incident reporting steps, and request forms in central document stores.

Common Implementation Challenges

  • Incomplete Coverage Across Diverse Environments: Difficulty installing and managing active security tools on developer workstations, personal devices, and short-term cloud servers.
  • User Bypass of Software Restrictions: Technical staff trying to bypass software controls or local admin limits to install unapproved utilities and scripts.
  • Outdated Security Definitions on Remote Devices: Remote worker laptops failing to sync with central management systems, leaving threat definitions outdated.
  • Alert Fatigue from High Volume Notifications: Security teams becoming overwhelmed by excessive low-priority alerts, which can delay responses to real security threats.
  • Evasion of Perimeter Gateway Filters: Advanced malware bypassing email and web filters by using encrypted web channels or password-protected file attachments.
  • Legacy System Incompatibility: Older operating systems and legacy business equipment being unable to support modern endpoint protection tools due to technical limits.
  • Unmonitored Use of External Storage Media: Weak enforcement of USB safety rules, allowing unvetted or infected storage drives to connect to network devices.
  • Disruption from Automatic Device Isolation: False alarm detections triggering automatic network blocks on key business systems, causing unannounced operational downtime.
  • Lack of Continuous Staff Awareness Training: Infrequent security refresher courses leaving employees vulnerable to evolving social engineering and phishing tactics.

How to Measure Effectiveness (KPIs)

  • Anti-Malware Deployment Coverage Rate: Measures the percentage of active user devices, servers, and cloud systems protected by active security software.
  • Outdated Threat Definition Rate: Tracks the percentage of business systems running security definition updates that are more than 24 hours out of date.
  • Mean Time to Detect Malware: Measures the average time elapsed between initial threat infection and detection by central security monitoring tools.
  • Mean Time to Contain Malware: Tracks the average time taken to isolate infected systems, stop bad processes, and block threat activity after detection.
  • Malware Incident Isolation Success Rate: Measures the percentage of security threats contained on a single device before spreading across the wider network.
  • Unauthorised Software Block Rate: Tracks the number of blocked attempts by users or systems to run unapproved files, scripts, or installer programs.
  • Phishing Training Completion Rate: Tracks the percentage of employees who complete mandatory anti-phishing and malware awareness modules on time.
  • System Backup Verification Rate: Measures the percentage of regular system backups checked and verified to ensure safe, malware-free data recovery.

ISO 27001 Annex A 8.7 does not work in isolation. It relies on several other controls:

ISO 27001 Protection Against Malware Explained – Annex A 8.7- ISO 27001.com
ISO 27001 Protection Against Malware Explained – Annex A 8.7
ISO 27001 Annex A 8.7