|
controlSI-3

Malicious Code Protection (SI-3)

Implement [organization-defined] malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code; Automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy and procedures; Configure malicious code protection mechanisms to: Address the receipt of false positives during malicious code detection and eradication and the resulting potential impact on the availabi

Security Baselines

LOWMODERATEHIGH
integritymalwareflaw-remediationmonitoring

Why These Connect

Maps To7

These are equivalent or closely aligned requirements in other frameworks.

Baselined In3

This control is included in the linked security baseline (LOW, MODERATE, or HIGH).

Supports53

These related controls work together — a change to one may affect the others.

Mitigates18

This control helps defend against or reduce the risk of the linked threat technique.

Enhances10

These enhancements add specific capabilities or refinements to the base control.

Cross-Framework Mappings(7)

PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-02PR.DS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
ISO 27001ISO/IEC 27001:20221 mappingFinal
NIST OLIR informative reference — SP 800-53 Rev 5 to ISO/IEC 27001:2022
PR.DS-01PR.DS-01Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-02PR.DS-02Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5
PR.DS-10PR.DS-10Final
NIST OLIR informative reference — Cybersecurity Framework v2.0 to SP 800-53 Rev 5

Organization-Defined Parameters(6)

SelectionSelection (one-or-more): signature-based / non-signature-based
Assignmentorganization-defined frequency
SelectionSelection (one-or-more): endpoint / network entry and exit points
SelectionSelection (one-or-more): block malicious code / quarantine malicious code / take {{ insert: param, si-03_odp.05 }}
Assignmentorganization-defined action
Assignmentorganization-defined personnel or roles

Control Enhancements(10)