Worm
What is Worm?
A type of malware that self-replicates and spreads across networks without requiring user interaction or a host programme. Worms can consume bandwidth, overload systems, and deliver additional malicious payloads.
Terms that appear alongside worm
Each of these is named in at least one of the same controls as worm. The number is how many controls name both.
- audit 7 shared controls
- integrity 6 shared controls
- nist 6 shared controls
- audit trail 5 shared controls
- availability 5 shared controls
- baseline 4 shared controls
- hipaa 3 shared controls
- chain of custody 3 shared controls
Frameworks that govern worm
What the standards actually require on worm
Requirements naming worm across 6 standards, quoted from the control text.
Security Dimension 3 Non-Repudiation per X.805 Clause 6.3: Non-repudiation provides means for preventing an individual or entity from denying having performed a particular action related to data by making available proof of various network-related actions (e.g...
X805-Dim3-Non-Repudiation-Proof-Origin-Delivery-Sender-Receiver-Denial-Prevention · ITU-T X.805 Security Dimension 3 - Non-Repudiation + Proof of Origin + Proof of Delivery + Sender + Receiver Denial Prevention + Digital Signatures + Timestamping + Audit Logs + Forensic Evidence + Court-Admissible Records →Incident Response capability is critical per FSA Cybersecurity Guidelines. (1) Incident Response Plan: (a) Documented IR Plan + per FFIEC IT Examination Handbook reference; (b) ISO/IEC 27035 Information Security Incident Management;
JP-FSA-CYB-Incident-Response-Playbooks-Containment-Eradication-Recovery-Post-Mortem-Tabletop-CSIRT · Japan FSA Cybersecurity Incident Response + Playbooks + Containment + Eradication + Recovery + Post-Mortem + Tabletop Exercises + CSIRT + FSA Notification + Customer Communication + Forensics + Lessons Learned →Malicious Code Controls. Controls to detect and block malicious code (or suitable mitigating controls) must be deployed at both endpoint and network level, covering viruses, ransomware, spyware, worms and trojans (para 53).
BMA-20 · Malicious Code Controls →ISMAP Cloud Operations covers the day-to-day security operations of cloud services. (1) Cloud Security Monitoring and Logging: 24x7 Security Operations Center (SOC) + SIEM Security Information and Event Management (Splunk + Microsoft Sentinel + IBM QRadar + Su...
ISMAP-CloudOperations-Monitoring-Logging-IncidentResponse-NISC-Reporting-Vulnerability-Change-SLA · ISMAP Cloud Operations - Security Monitoring + SIEM + Logging + Incident Response + NISC Reporting + Vulnerability Management + Penetration Testing + Change Management + SLA Management →RBI AA Audit + Logging + Authentication establishes the assurance layer for the AA ecosystem. (1) IT System Audit: per RBI Cyber Security Framework + RBI IT Guidelines for NBFC-AA - bi-annual or annual independent IT system audit by qualified auditors (CISA +...
RBI-AA-Audit-Logging-IT-System-Audit-Consent-Lifecycle-Authentication · RBI AA Audit + Logging - IT System Audit + Consent Lifecycle Logging + Customer Authentication + Bi-Annual Audit + RBI Inspection + Sahamati Compliance Reporting →Directions 5-7 establish the technical baseline for evidence preservation + forensic readiness + time integrity. Direction 5: All service providers + intermediaries + data centres + body corporates + government organisations shall mandatorily enable logs of al...
CERTIN-Logging-180DayRetention-IndiaLocalisation-NTP-NIC-NPL-CERTIn-Access-Dir5to7 · CERT-In Directions 5-7 System Logging + Clock Synchronization - 180-Day Log Retention in India + NTP Synchronisation with NIC/NPL + Log Availability to CERT-In on Order →Questions people ask about worm
What is Worm?
Why is Worm important for compliance?
Which compliance frameworks address Worm?
Where can I learn more about Worm?
See how Worm applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.