ISO/IEC 27001:2022 Annex A · Control 8.7
Protection Against Malware: A Practical Implementation Guide
Prevent, detect and recover from malicious code across endpoints, servers, email, cloud and software delivery.
This control concerns protection against malware supported by appropriate user awareness.
What should the control achieve?
- Malware entry and execution paths are reduced.
- Detection covers relevant platforms.
- Alerts receive timely response.
- Recovery is tested and lessons improve defenses.
Step-by-step implementation
Map malware paths
Consider email, web, removable media, remote access, suppliers and software updates.
Prevent execution
Use filtering, application control, macros restrictions, least privilege and patching.
Deploy detection
Use endpoint, server, email, network and cloud controls with central visibility.
Tune and monitor
Assign alert severity, exclusions, owners and response targets.
Prepare response
Isolate devices, preserve evidence, reset credentials and assess spread.
Validate recovery
Restore trusted systems and test backups and reimaging.
What this could look like in practice
Email sandboxing and endpoint behavior detection block common payloads. Suspected ransomware automatically isolates the endpoint, alerts Security and triggers a playbook that checks identity, network spread and backups.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Attachments and links are filtered and sandboxed. | Gateway log | |
| Endpoint | EDR monitors behavior and isolates threats. | Detection record |
| Exception | Tool exclusion needs owner, scope and expiry. | Exception approval |
| Recovery | Device is rebuilt and credentials reset. | Incident closure |
Implementation evidence
- Malware policy
- Coverage inventory
- Secure configurations
- Alert records
- Exclusion register
- Response playbook
- Recovery tests
- Awareness results
Useful metrics
- Protected assets coverage
- Critical malware alerts within target
- Expired exclusions
- Repeat infections
Common mistakes
- Assuming one tool blocks every attack.
- Disabling protection for performance without review.
- Ignoring Linux, mobile and cloud workloads.
- Restoring before removing persistence.
- Failing to test backups against ransomware.
Questions an auditor may ask
- Which malware paths are addressed?
- How is coverage verified?
- Show an alert response.
- How are exclusions controlled?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.