Back to Corporate Standards
CS-02 · Corporate Standards

Anti-Malware Policy

Endpoint, server, and email defenses against malicious code.

DOCUMENT

CS-02

OWNER

Director of Security Engineering

EFFECTIVE

January 1, 2026

REVIEWED

March 15, 2026

Class · PUBLIC·Review cycle · Annual

Purpose

This Policy defines the controls used to protect company information systems from malicious software including viruses, worms, trojans, ransomware, fileless malware, rootkits, and supply-chain code injections.

It implements ISO/IEC 27001 A.8.7 (Protection against malware) and the NIST CSF 2.0 PR.PS-05 control objective.

Required controls

  • 01Endpoint Detection & Response (EDR) installed on every workstation, laptop, and server. Tamper protection enforced.
  • 02Email gateway scanning with link-rewriting, attachment sandboxing, and impersonation protection.
  • 03DNS-layer filtering for off-network and on-network devices.
  • 04Application allow-listing on all production servers and high-value workstations (executive, finance, security operations).
  • 05USB and removable-media controls — block by default, allow-list approved devices only.
  • 06Daily signature updates and weekly behavioral model updates, monitored by Security Operations.
  • 07Quarterly anti-malware effectiveness testing using benign EICAR strings and red-team controlled samples.

Detection and response

All EDR alerts of severity Medium or higher are triaged within 15 minutes by Security Operations. Confirmed malware triggers immediate host isolation, evidence preservation, and execution of the relevant Incident Response runbook.

Suspected ransomware activity invokes the most aggressive containment posture — network segmentation collapse, immediate forensic snapshot, and notification of the Incident Commander.

User obligations

  • 01Do not disable, modify, or attempt to bypass anti-malware controls.
  • 02Report any suspected infection within 1 hour of discovery via the Incident Reporter channel.
  • 03Do not execute software from untrusted sources, including personal email attachments and consumer download portals.
  • 04Connect only to corporate-approved networks for any production system access.

Exceptions

Exceptions to this Policy require written approval from the CISO and are documented with a compensating control plan and an expiration date not exceeding 90 days.

/CONTROLLED_DOCUMENT

This document is the official, controlled version of CS-02 — Anti-Malware Policy. Printed or downloaded copies are uncontrolled. Questions about this document should be directed to compliance@alexasecurity.net.

VERSION

2026.1

REVIEWED

March 15, 2026

NEXT REVIEW

Annual