Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.7

Protection Against Malware: A Practical Implementation Guide

Prevent, detect and recover from malicious code across endpoints, servers, email, cloud and software delivery.

This control concerns protection against malware supported by appropriate user awareness.

Practical interpretation: Endpoint antivirus is one layer. Effective protection combines hardening, filtering, behavior detection, least privilege, patching, backups and prepared response.

What should the control achieve?

  • Malware entry and execution paths are reduced.
  • Detection covers relevant platforms.
  • Alerts receive timely response.
  • Recovery is tested and lessons improve defenses.

Step-by-step implementation

1

Map malware paths

Consider email, web, removable media, remote access, suppliers and software updates.

2

Prevent execution

Use filtering, application control, macros restrictions, least privilege and patching.

3

Deploy detection

Use endpoint, server, email, network and cloud controls with central visibility.

4

Tune and monitor

Assign alert severity, exclusions, owners and response targets.

5

Prepare response

Isolate devices, preserve evidence, reset credentials and assess spread.

6

Validate recovery

Restore trusted systems and test backups and reimaging.

What this could look like in practice

Email sandboxing and endpoint behavior detection block common payloads. Suspected ransomware automatically isolates the endpoint, alerts Security and triggers a playbook that checks identity, network spread and backups.

ActivityPractical implementationEvidence
EmailAttachments and links are filtered and sandboxed.Gateway log
EndpointEDR monitors behavior and isolates threats.Detection record
ExceptionTool exclusion needs owner, scope and expiry.Exception approval
RecoveryDevice is rebuilt and credentials reset.Incident closure

Implementation evidence

  • Malware policy
  • Coverage inventory
  • Secure configurations
  • Alert records
  • Exclusion register
  • Response playbook
  • Recovery tests
  • Awareness results

Useful metrics

  • Protected assets coverage
  • Critical malware alerts within target
  • Expired exclusions
  • Repeat infections

Common mistakes

  • Assuming one tool blocks every attack.
  • Disabling protection for performance without review.
  • Ignoring Linux, mobile and cloud workloads.
  • Restoring before removing persistence.
  • Failing to test backups against ransomware.

Questions an auditor may ask

  • Which malware paths are addressed?
  • How is coverage verified?
  • Show an alert response.
  • How are exclusions controlled?
Implementation test: Run a safe malware simulation and verify prevention, detection, isolation, investigation, communication and recovery.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.