Skip to content

Malware

What is Malware?

Any software intentionally designed to cause damage to a computer, server, client, or computer network. Malware types include viruses, worms, trojans, ransomware, spyware, adware, and rootkits.

Information Security

Each of these is named in at least one of the same controls as malware. The number is how many controls name both.

What the standards actually require on malware

Requirements naming malware across 6 standards, quoted from the control text.

PCI DSS 4.010 controls

Audit logs for the anti-malware solution are enabled and retained in accordance with Requirement 10.5.1.

5.3.4 · Audit logs for anti-malware enabled

Assessor tests that the device or web filter blocks malicious files when downloaded via browser from a controlled test URL.

CE-PLUS.4 · Malware Protection Test - Web Download
C5 (Germany)4 controls

Configure production system components with malware protection as the policy prescribes, and where signature and behaviour based detection software is used, update its detection content at least once every day.

C5-OPS-05 · Protection Against Malware - Implementation

Deploy modern anti-malware solutions with cloud-delivered protection, real-time scanning, and behaviour monitoring.

ES-2 · Use modern anti-malware software

Malware detection. The company should deploy malware detection and prevention appropriate to IT and OT, recognising constraints on OT systems.

BIMCO-8.2 · Malware detection
CIS Controls v83 controls

Configure automatic updates for anti-malware signature files on all enterprise assets.

CIS-10.2 · Configure Automatic Anti-Malware Signature Updates

Questions people ask about malware

What is Malware?
Any software intentionally designed to cause damage to a computer, server, client, or computer network. Malware types include viruses, worms, trojans, ransomware, spyware, adware, and rootkits.
Why is Malware important for compliance?
Malware is a key concept in Information Security. Understanding malware helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Malware?
Malware appears in the requirement text of PCI DSS 4.0, Cyber Essentials Plus, C5 (Germany), Azure Security Benchmark, BIMCO Cyber Security. Across these standards we have identified 29 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Malware?
Explore our compliance framework pages to see how malware applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Malware applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.