Control Mapping Readerplace a control, see the map

NIST800-SI-3 SI-3 Malicious Code Protection

NIST800-SI-3 in NIST SP 800-53 Rev 5 (NIST SP 800-53 Rev 5, Release 5.2.0). All NIST SP 800-53 Rev 5 controls held. Open NIST SP 800-53 Rev 5 on the standards site.

The control as we hold it

SI-3 Malicious Code Protection. a. Implement [Selection (one or more): signature-based; non-signature-based] malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code; b. Automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy and procedures; c. Configure malicious code protection mechanisms to: 1. Perform periodic scans of the system [Assignment: organization-defined frequency] and real-time scans of files from external sources at [Selection (one or more): endpoint; network entry and exit points] as the files are downloaded, opened, or executed.

Reviewed and closest counterparts in the other frameworks

Reviewed rows come from a released pair; a closest match is the nearest held text and is not a reviewed row.

SOC 2

HIPAA Security Rule

What an auditor commonly asks for

General guidance for this control area (domain: SI - System and Information Integrity), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control