HomeControl Library › 3.14.2
3.14 System & Information Integrity5 ptsAlso Level 1

3.14.2 — Run anti-malware protection

Provide protection from malicious code at designated locations within organizational systems.

Malicious-code protection is deployed and kept current everywhere it should be.

What it actually means

Endpoint protection / anti-malware (ideally EDR) deployed at the right places — endpoints, servers, email gateways — and actually kept up to date. Coverage and currency are what's checked: protection that's installed but disabled or out of date doesn't count.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library