What to Provide
(1) The documented policy/procedure that defines your organization's process for utilizing anti-malware.
(2) Evidence demonstrating anti-malware enabled on all production systems and/or employee workstations.
Evidence Format
(1) Word/PDF document
(2) Screenshots or exported images in a common image file type, such as .jpg, .png, or .pdf.
Additional Guidance
For each production system or employee workstation, evidence should demonstrate:
Scan schedules
Virus definition update schedules
Notification schedules
An example of a notification or alert message
Associated Unified Control ID | Associated Framework Control |
CTRL-822 | LCL-45 |