Security requirement
- a.Implement malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.
- b.Update malicious code protection mechanisms as new releases are available in accordance with configuration management policies and procedures.
- c.Configure malicious code protection mechanisms to:
- 1.Perform scans of the system [Organization-defined: frequency] and real-time scans of files from external sources at endpoints or system entry and exit points as the files are downloaded, opened, or executed; and
- 2.Block malicious code, quarantine malicious code, or take other mitigation actions in response to malicious code detection.
Discussion
Malicious code insertions occur through the exploitation of system vulnerabilities. Malicious code can be inserted into the system in a variety of ways, including email, the internet, and portable storage devices. Malicious code includes viruses, worms, Trojan horses, and spyware. Malicious code can be encoded in various formats, contained in compressed or hidden files, or hidden in files using techniques such as steganography. Malicious code may be present in commercial off-the-shelf software and custom-built software and could include logic bombs, backdoors, and other types of attacks that could affect organizational mission and business functions. Periodic scans of the system and real-time scans of files from external sources as files are downloaded, opened, or executed can detect malicious code. Malicious code protection mechanisms can also monitor systems for anomalous or unexpected behaviors and take appropriate actions. Malicious code protection mechanisms include signature- and non-signature-based technologies. Non-signature-based detection mechanisms include artificial intelligence techniques that use heuristics to detect, analyze, and describe the characteristics or behavior of malicious code and to provide controls against such code for which signatures do not yet exist or for which existing signatures may not be effective. Malicious code for which active signatures do not yet exist or may be ineffective includes polymorphic malicious code (i.e., code that changes signatures when it replicates). Non-signature-based mechanisms include reputation-based technologies. Pervasive configuration management, anti-exploitation software, and software integrity controls may also be effective in preventing unauthorized code execution. If malicious code cannot be detected by detection methods or technologies, organizations can rely on secure coding practices, configuration management and control, trusted procurement processes, and monitoring practices to help ensure that the software only performs intended functions. Organizations may determine that different actions are warranted in response to the detection of malicious code. For example, organizations can define actions to be taken in response to the detection of malicious code during scans, malicious downloads, or malicious activity when attempting to open or execute files.
Tailoring decisions required
Resolve these values through the governing organization’s approved tailoring and risk-management process before declaring the requirement implemented.
Implementation perspective
Treat Malicious Code Protection as a CUI protection outcome that must be reflected in the system boundary, documented implementation, operational behavior, and assessment evidence. Pay particular attention to flaw remediation, malicious-code protection, monitoring, integrity, and trustworthy handling of CUI.
- Confirm the requirement is in scope for the CUI system components, services, users, and external connections being assessed.
- Resolve every organization-defined parameter through an approved governance and tailoring process.
- Map each clause of the requirement to an accountable owner, implementation mechanism, and evidence source.
- Verify that inherited and shared implementations are supported by current provider evidence and responsibility boundaries.
- Collect evidence during normal operation and review changes, exceptions, and deficiencies on a risk-based cadence.
Questions to ask
- Which CUI assets, data flows, users, and services are protected by this requirement?
- Which portions are implemented locally, inherited, shared, or not applicable, and what evidence supports that determination?
- Do the system security plan, deployed configuration, operating process, and assessment evidence tell the same story?
- What change, incident, or threshold should trigger reassessment?
Evidence and validation
- patch and remediation records
- malware protection configuration
- monitoring alerts and response records
- integrity validation and exception reports
Common failure patterns
- patch compliance hiding unsupported assets
- alerts generated without response ownership
- exceptions that never expire
- integrity monitoring excluding critical configurations
Assessment objectives and methods
Assessment objectives (6)
- a.
malicious code protection mechanisms are implemented at system entry and exit points to detect malicious code.
- a.
malicious code protection mechanisms are implemented at system entry and exit points to eradicate malicious code.
- b.
malicious code protection mechanisms are updated as new releases are available in accordance with configuration management policy and procedures.
- c.1.
malicious code protection mechanisms are configured to perform scans of the system [Organization-defined: frequency].
- c.2.
malicious code protection mechanisms are configured to block malicious code, quarantine malicious code, or take other actions in response to malicious code detection.
- c.1.
malicious code protection mechanisms are configured to perform real-time scans of files from external sources at endpoints or system entry and exit points as the files are downloaded, opened, or executed.
Examine
- system and information integrity policy and procedures
- configuration management policy and procedures
- procedures for malicious code protection
- records of malicious code protection updates
- system design documentation
- system configuration settings
- scan results from malicious code protection mechanisms
- record of actions initiated by malicious code protection mechanisms in response to malicious code detection
- system audit records
- system security plan
- other relevant documents or records
Interview
- personnel responsible for malicious code protection
- personnel with system installation, configuration, or maintenance responsibilities
- personnel with information security responsibilities
- system administrators
Test
- processes for employing, updating, and configuring malicious code protection mechanisms
- processes for addressing the detection of false positives and resulting potential impacts
- mechanisms for supporting or implementing, employing, updating, and configuring malicious code protection mechanisms
- mechanisms for supporting or implementing malicious code scanning and the execution of subsequent actions
Source NIST SP 800-53 controls
These controls are referenced by the official SP 800-171 Rev. 3 OSCAL record. Open the corresponding control pages for complete control text, enhancements, D3FEND mappings, and related learning.
Authoritative sources
- NIST SP 800-171 Revision 3 official publication ↗
- NIST SP 800-171A Revision 3 official publication ↗
- NIST OSCAL Content release used for this import ↗
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. The official publications, the responsible federal agency, and the governing contract or agreement determine applicability, tailoring, assessment depth, and required implementation.