Skip to content

Cyber Essentials – How to Implement the Malware Key Control

Malware is short for malicious software, which is a type of software designed to infiltrate computers and networks in order to cause damage or to steal sensitive information. Malware is a broad term that includes viruses, ransomware, spyware and many other forms of malicious code. Many businesses succumb to this type of cyber threat, leading to serious financial, legal and reputational consequences, so it’s not hard to understand why it’s one of the key controls in the Cyber Essentials framework.

The Scope and Goals of the Malware Key Control

This control applies to: Desktop computers, laptops, tablets, and mobile phones.

Its objectives: To restrict malware and untrusted software from causing damage and accessing sensitive data.

An example of applying this key control is deploying professional antivirus software across your workplace’s devices. This software will continually scan for and prevent malware from accessing these devices, and therefore your network and the sensitive information held within it.

There are three key requirements for the malware key control:

  • Implementing anti-malware software: this software must be updated daily (this can be automatically done), configured to automatically scan files and web pages whenever they are accessed, and prevent access to malicious websites (these can be blacklisted, or ruled out in other words), unless there is a clear, purposeful and documented need for doing so.
  • Application whitelisting: Only use trusted, organisationally approved and documented applications in the organisation. Only download official and trusted applications onto devices, and ensure that a list of approved applications is maintained in the organisation.
  • Application sandboxing: If you use any code or data (the programming languages that bring computers and apps to life) of an unknown origin, it needs to be run in a sandbox, which is an isolated environment from your network. This includes data stores, other sandboxed apps, sensitive equipment such as cameras and GPS devices, and local network access.

malware

Your Practical Guide to Applying the Malware Key Control

Here’s how to apply the malware key control requirements in practice. Remember to document these implementations so that you can demonstrate their application in the certification process.

Install Antivirus Software

Choose a reputable antivirus solution and install it on all devices, including computers, laptops, and mobile devices. Ensure the antivirus software is kept up-to-date to defend against the latest malware threats.

Configure your Antivirus Software to Requirements

To meet the requirements, configure your antivirus software across your organisation to automatically update with the latest security patches on a daily basis.

Additionally, make sure you have a defined blacklist of websites (many antivirus software will automatically deploy and update a comprehensive blacklist for you). Check to ensure the antivirus software automatically scans files and websites for threats.

Create a whitelist of approved applications

A key way to stay protected, is to ensure that applications are sourced from trustworthy sources such as official and widely recognised organisations. Create a list of approved applications for your organisation to serve as a documentable guide for trustworthy applications your organisation should use.

Create a secure sandbox environment if needed

Should you ever test or come across code from an unknown source, having a sandbox environment to test it in is crucial. This environment will be isolated from your network, preventing possible harm if there are any malicious threats. Of course, to meet the requirement around this, organisations can also avoid unrecognised software, code and hardware from unreputable or unknown sources.

For non-technical teams, it is possible to implement sandboxes via standalone software or cloud-based services. However, for best practice and peace of mind, it can be very helpful to get the support of an IT support provider for this.

Get your FREE cyber risk traffic light report

Our Cyber Risk Traffic Light Report is designed to help businesses audit their cybersecurity posture, enabling them to find risk areas and security gaps and to address them with actionable insights. Get started with your cybersecurity journey by getting your own Cyber Risk Traffic Light Report  today.

Back To Top