<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: In which policy to place company anti-malware requirements in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/In-which-policy-to-place-company-anti-malware-requirements/m-p/40409#M169</link>
    <description>&lt;P&gt;It can be referenced from several place as anti malware controls aren't necessarily just a software product on endpoints.&amp;nbsp; So at a policy level you'd have a statement that the standard antimalware product had to be part of every build and that it mustn't be disabled or uninstalled.&amp;nbsp; At a standards level you'd define how the product must be configured in terms of its features and their management.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may also have other malware controls in place around ingress of data e.g. email and web filtering, deep pack inspection for malware, restrictions on removable media etc.&amp;nbsp; You may also want to restrict what programs can download and/or execute, so you're only running known good software.&amp;nbsp; Some of those you'd need to put in your AUP to set expectations on staff behaviour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Oct 2020 12:10:54 GMT</pubDate>
    <dc:creator>Steve-Wilme</dc:creator>
    <dc:date>2020-10-30T12:10:54Z</dc:date>
    <item>
      <title>In which policy to place company anti-malware requirements</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/In-which-policy-to-place-company-anti-malware-requirements/m-p/40405#M168</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am currently refreshing our policies, however I am not sure what is the best place to place requirements for the antimalware client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would you place these in an independent policy (e.g. Antimalware policy) or as part of another one?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:40:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/In-which-policy-to-place-company-anti-malware-requirements/m-p/40405#M168</guid>
      <dc:creator>JulienB</dc:creator>
      <dc:date>2023-10-09T09:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: In which policy to place company anti-malware requirements</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/In-which-policy-to-place-company-anti-malware-requirements/m-p/40409#M169</link>
      <description>&lt;P&gt;It can be referenced from several place as anti malware controls aren't necessarily just a software product on endpoints.&amp;nbsp; So at a policy level you'd have a statement that the standard antimalware product had to be part of every build and that it mustn't be disabled or uninstalled.&amp;nbsp; At a standards level you'd define how the product must be configured in terms of its features and their management.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may also have other malware controls in place around ingress of data e.g. email and web filtering, deep pack inspection for malware, restrictions on removable media etc.&amp;nbsp; You may also want to restrict what programs can download and/or execute, so you're only running known good software.&amp;nbsp; Some of those you'd need to put in your AUP to set expectations on staff behaviour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 12:10:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/In-which-policy-to-place-company-anti-malware-requirements/m-p/40409#M169</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2020-10-30T12:10:54Z</dc:date>
    </item>
  </channel>
</rss>

