3.14 System & Information Integrity3 ptsAlso Level 1

3.14.5 — Scan systems and files

Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.

Periodic system scans plus real-time scanning of incoming files.

What it actually means

Run scheduled full scans and real-time/on-access scanning so files from outside are checked as they're downloaded, opened, or run. Standard EDR/AV behavior — confirm it's enabled, scheduled, and covering the scope.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.

Calculate your SPRS score →Draft your SSP language →

Connected requirements

More in System & Information Integrity (3.14)

← Back to the Control Library

The GovCon Compliance Brief
Get the next regulation change explained in plain English.

One CMMC / NIST 800-171 update, decoded, every other week. No spin, no sales pitch. Free.