ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 5. ISO 27001 Annex A - 8 ...
  5. ISO 27001 Annex A 8.7 Protection against malware

ISO 27001 Annex A 8.7 Protection against malware

What is ISO 27001 Annex A 8.7 – Protection Against Malware?

ISO 27001 Annex A 8.7 focuses on implementing appropriate measures to protect information and associated assets against malware.

Malware is malicious software designed to damage systems, disrupt operations, steal information, gain unauthorized access, or perform other unauthorized activities.

Examples include:

  • Viruses
  • Worms
  • Trojans
  • Ransomware
  • Spyware
  • Keyloggers
  • Rootkits
  • Botnet malware
  • Cryptominers
  • Remote-access malware
  • Malicious scripts
  • Fileless malware
  • Malicious macros
  • Other unwanted or harmful software

Simple Explanation

Prevent malware from entering your environment, detect it when it does, respond quickly, and reduce the chance of it spreading.

For a modern startup, malware protection is not limited to installing antivirus software.

A practical malware-defense strategy may include:

Endpoint protection + patching + email security + web protection + application controls + user awareness + monitoring + incident response


Why is Protection Against Malware Important?

Malware can enter an organization through many different routes.

For example:

Phishing Email
      ↓
Malicious Attachment
      ↓
Employee Opens File
      ↓
Malware Executes
      ↓
Credential Theft
      ↓
Lateral Movement
      ↓
Data Access / Encryption

Malware can affect:

  • Laptops
  • Desktops
  • Servers
  • Mobile devices
  • Cloud workloads
  • Virtual machines
  • Containers
  • Applications
  • Email systems
  • File shares
  • Removable media

Common Malware Risks

  • Ransomware
  • Credential theft
  • Data theft
  • Unauthorized remote access
  • Business disruption
  • Data encryption
  • Destruction of information
  • System compromise
  • Financial loss
  • Reputational damage
  • Customer impact

Simple Principle

Malware protection should be a layered process, not a single antivirus installation.


What Does ISO 27001 Annex A 8.7 Require?

The organization should implement appropriate measures to protect against malware.

The exact controls should be determined based on:

  • Risk assessment
  • Technology environment
  • Types of devices
  • Information sensitivity
  • Threat environment
  • Remote working
  • Cloud usage
  • Business requirements
  • Regulatory requirements
  • Customer requirements

A small SaaS startup does not necessarily need the same malware-security architecture as a large bank.

However, it should be able to demonstrate that it has considered malware risks and implemented reasonable controls.


What is Malware Protection?

Malware protection consists of multiple layers.

Prevention

Stop malware from entering or executing.

Detection

Identify suspicious or malicious activity.

Response

Contain and remove the threat.

Recovery

Restore affected systems and information.

A simple model is:

Prevent → Detect → Contain → Remove → Recover → Learn


Activities Required to Implement Annex A 8.7

1. Identify Where Malware Could Affect the Organization

Start by identifying assets that could be exposed to malware.

Examples:

  • Employee laptops
  • Desktops
  • Servers
  • Cloud workloads
  • Mobile devices
  • File storage
  • Email
  • SaaS applications
  • Development environments
  • CI/CD systems
  • Removable media

2. Deploy Endpoint Protection

Organizations should implement appropriate endpoint protection.

Depending on risk, this could include:

  • Antivirus
  • Endpoint Detection and Response (EDR)
  • Endpoint protection platforms
  • Host-based security controls
  • Application control
  • Device security management

For example:

Company Laptop
      ↓
Endpoint Protection
      ↓
Malware Detection
      ↓
Alert
      ↓
Security Team
      ↓
Investigation / Isolation

For higher-risk environments, EDR may provide capabilities beyond traditional antivirus.


3. Keep Systems Updated

Malware frequently exploits known vulnerabilities.

Therefore, malware protection should be connected with:

A.8.8 – Management of Technical Vulnerabilities

Important updates may include:

  • Operating-system patches
  • Browser updates
  • Application updates
  • Security-agent updates
  • Firmware updates
  • Server updates
  • Third-party software updates

A device with malware protection but a severely outdated operating system can still present significant risk.


4. Protect Email

Email is a common malware-delivery channel.

Organizations should consider controls such as:

  • Spam filtering
  • Malware scanning
  • Attachment scanning
  • URL protection
  • Phishing protection
  • Domain protection
  • Sender authentication
  • Quarantine mechanisms

Users should be educated about suspicious:

  • Attachments
  • Links
  • Login pages
  • Executable files
  • Office documents
  • Unexpected invoices
  • Password-reset requests

5. Control Malicious Attachments

Potentially dangerous file types may require additional controls.

Examples include:

  • Executables
  • Scripts
  • Macro-enabled documents
  • Compressed archives
  • Disk images

The organization should determine appropriate restrictions based on its environment and business requirements.


6. Control Software Installation

Users should not be allowed to install arbitrary software on business devices without appropriate authorization.

Risks include:

  • Malware
  • Unlicensed software
  • Vulnerable software
  • Malicious browser extensions
  • Unapproved remote-access tools

A startup may use:

  • Standard software lists
  • Application allowlisting where appropriate
  • Endpoint management
  • User restrictions
  • Software-installation approval

7. Restrict Administrative Privileges

Malware can have a greater impact when executed by an administrator.

For example:

Standard User
      ↓
Malware Execution
      ↓
Limited Permissions

versus:

Administrator
      ↓
Malware Execution
      ↓
High Privileges
      ↓
Greater System Impact

This connects A.8.7 with A.8.2 – Privileged Access Rights.

Users should not have unnecessary administrator privileges.


8. Protect Removable Media

USB drives and other removable media can introduce malware.

Controls may include:

  • Restricting unauthorized USB devices
  • Scanning removable media
  • Disabling unnecessary removable-media access
  • Encrypting sensitive removable media
  • Authorizing business use
  • Monitoring where appropriate

This also connects with A.7.10 – Storage Media.


9. Protect Web Browsing

Websites can deliver malware through:

  • Malicious downloads
  • Drive-by attacks
  • Malicious advertisements
  • Fake software updates
  • Browser exploits
  • Phishing pages

Organizations may use:

  • Secure DNS
  • Web filtering
  • Browser security
  • Endpoint protection
  • URL reputation controls
  • Download restrictions

The controls should be appropriate to the organization’s risk.


10. Protect Cloud Workloads

Cloud does not eliminate malware risk.

Malware may affect:

  • Virtual machines
  • Containers
  • Kubernetes workloads
  • Build environments
  • Developer systems
  • Cloud-hosted applications

Organizations should determine which malware controls are appropriate for their cloud architecture.

For example:

Endpoint protection may be highly relevant for employee laptops, while workload security and image scanning may be more relevant for cloud workloads.


11. Protect Development Environments

Software-development environments can also be targeted.

Potential risks include:

  • Malicious packages
  • Compromised dependencies
  • Malicious code
  • Infected developer systems
  • Compromised CI/CD tools
  • Malicious scripts

Therefore, malware protection should be considered alongside:

  • Secure coding
  • Dependency management
  • Vulnerability scanning
  • Source-code security
  • CI/CD security

12. Detect Malware

Detection mechanisms may include:

  • Antivirus alerts
  • EDR alerts
  • SIEM alerts
  • Email-security alerts
  • Cloud-security alerts
  • File-integrity monitoring
  • Suspicious process detection
  • Threat-intelligence indicators

The organization should determine which events require investigation.


13. Respond to Malware Incidents

A malware incident should have a defined response process.

For example:

Malware Detected
      ↓
Alert
      ↓
Investigate
      ↓
Isolate Device/System
      ↓
Contain Threat
      ↓
Remove Malware
      ↓
Reset Compromised Credentials
      ↓
Restore if Required
      ↓
Investigate Root Cause
      ↓
Lessons Learned

This connects with:

  • A.5.24 – Incident Management Planning and Preparation
  • A.5.25 – Assessment and Decision on Information Security Events
  • A.5.26 – Response to Information Security Incidents
  • A.5.27 – Learning from Information Security Incidents

14. Educate Employees

Technology alone cannot eliminate malware risk.

Employees should understand:

  • Phishing
  • Malicious attachments
  • Suspicious links
  • Fake login pages
  • USB risks
  • Software downloads
  • Social engineering
  • Reporting procedures

Training should explain what employees should do, not simply tell them:

“Do not click suspicious links.”

For example:

“If you accidentally open a suspicious attachment, disconnect from the network if instructed by your incident procedure and immediately report the event to IT/security.”


15. Define Malware Reporting

Employees should have a simple way to report:

  • Suspicious emails
  • Malware alerts
  • Unexpected pop-ups
  • Unknown software
  • Unusual device behavior
  • Suspicious browser activity
  • Lost or compromised devices

This connects with A.6.8 – Information Security Event Reporting.


16. Maintain Malware Protection

Security tools should themselves remain operational.

Consider:

  • Agent health
  • Signature/update status
  • EDR connectivity
  • Policy configuration
  • License status
  • Coverage
  • Unsupported devices
  • Disabled protection
  • Exceptions

An antivirus product installed six months ago but no longer updating is not effective protection.


Startup Example

Example: 50-Person SaaS Startup

The startup has:

  • Windows laptops
  • MacBooks
  • Mobile devices
  • AWS workloads
  • GitHub
  • Google Workspace
  • Slack
  • CRM
  • CI/CD

Initially, the company relies only on basic antivirus.

Identified Risks

  • Phishing
  • Malicious attachments
  • Browser-based malware
  • Unapproved software
  • Compromised developer laptops
  • USB malware
  • Cloud workload compromise

Improved Model

The startup implements:

Managed endpoint protection

↓

Automatic security updates

↓

MFA

↓

Restricted local administrator privileges

↓

Email malware/phishing protection

↓

Software-installation controls

↓

Employee security awareness

↓

Malware reporting

↓

EDR/security monitoring

↓

Incident response

This provides a layered approach without requiring a large security team.


Malware Protection Matrix

ThreatPreventive ControlDetectionResponse
RansomwareEDR, patching, restricted privilegesEDR alertsIsolate device
Phishing attachmentEmail filteringEmail/security alertInvestigate
Malicious downloadWeb protectionEndpoint detectionBlock/isolate
USB malwareUSB controls/scanningEndpoint detectionRemove/isolate
Malicious softwareApplication controlsEDRUninstall/block
Cloud workload malwareWorkload securityCloud monitoringIsolate workload
Compromised developer deviceEDR + patchingSecurity monitoringIsolate/reset credentials

Malware Protection Register

A simple register could contain:

Asset/AreaProtectionStatusOwnerReview
Employee LaptopsEDRActiveITMonthly
Mac DevicesEndpoint SecurityActiveITMonthly
Windows DevicesEDRActiveITMonthly
EmailMalware FilteringActiveITMonthly
Cloud WorkloadsAppropriate Workload ControlsActiveDevOpsMonthly
USBRestricted/ControlledActiveITQuarterly
ServersEndpoint/Workload ProtectionActiveDevOpsMonthly

Malware Incident Example

Suppose an employee opens a malicious attachment.

The endpoint security system detects suspicious behavior.

Response

Malware Alert
     ↓
Security Investigation
     ↓
Endpoint Isolated
     ↓
User Notified
     ↓
Malware Removed
     ↓
Credentials Reviewed/Reset
     ↓
Logs Investigated
     ↓
Other Systems Checked
     ↓
Endpoint Restored
     ↓
Incident Closed
     ↓
Lessons Learned

The incident should be recorded according to the organization’s incident-management process.


What Evidence Can an Auditor Ask For?

An auditor may request:

Policies

  • Malware Protection Policy
  • Endpoint Security Policy
  • Acceptable Use Policy
  • Incident Management Policy
  • Patch Management Procedure

Technical Evidence

  • Endpoint protection deployment
  • EDR dashboard
  • Antivirus configuration
  • Security-agent status
  • Malware detection reports
  • Email-security configuration
  • Web-security configuration

Patch Evidence

  • Patch reports
  • Vulnerability reports
  • Update status
  • Exception records

Awareness Evidence

  • Security awareness training
  • Phishing awareness material
  • Employee acknowledgements
  • Training completion records

Incident Evidence

  • Malware incidents
  • Security alerts
  • Investigation records
  • Device-isolation records
  • Lessons-learned records

Monitoring

  • EDR alerts
  • SIEM alerts
  • Security monitoring records

ISO 27001 Annex A 8.7 Audit Checklist

QuestionYes/NoEvidence
Has malware risk been assessed?Risk assessment
Are endpoints protected against malware?EDR/AV dashboard
Is protection centrally managed where appropriate?Management console
Are security agents operational and updated?Agent status
Are systems regularly patched?Patch reports
Is email malware protection implemented?Email-security configuration
Are malicious attachments appropriately controlled?Email settings
Is unauthorized software installation controlled?Endpoint policy
Are administrator privileges restricted?Endpoint/user settings
Are removable media risks addressed?USB policy
Are malware events monitored?EDR/SIEM logs
Is there a malware response procedure?Incident procedure
Are employees trained about malware risks?Training records
Can employees report suspected malware?Reporting procedure
Are malware incidents investigated?Incident records
Are malware controls periodically reviewed?Review records

Common Mistakes

1. Thinking Antivirus Alone Is Enough

Modern malware protection should be layered.


2. Ignoring Mac and Mobile Devices

Malware protection requirements should consider the organization’s actual endpoint environment rather than assuming only Windows devices matter.


3. No Central Visibility

If IT does not know whether security software is installed and operational, coverage gaps can remain unnoticed.


4. Ignoring Patch Management

Malware frequently exploits vulnerabilities.

Protection against malware should therefore connect with vulnerability management.


5. Allowing Everyone to Be Local Administrator

Excessive privileges can increase the impact of malware.


6. Ignoring Email

Email remains an important malware and phishing delivery channel.


7. Ignoring Cloud Workloads

Cloud infrastructure can also be compromised by malicious software, scripts, packages, or compromised credentials.


8. No Incident Response

Detecting malware is not enough.

The organization should know what happens after detection.


9. No User Reporting Process

Employees should know how and where to report suspected malware.


10. No Evidence of Effectiveness

Simply purchasing an endpoint-security product does not demonstrate that devices are actually protected.


Practical Startup Implementation Model

A startup can implement Annex A 8.7 using:

Assess → Prevent → Protect → Detect → Respond → Recover → Learn

Assess

Identify malware risks and affected assets.

Prevent

Reduce the chance of malware entering the environment.

Protect

Deploy endpoint, email, application, and other appropriate controls.

Detect

Monitor for malicious activity.

Respond

Contain and investigate malware incidents.

Recover

Restore affected devices and systems.

Learn

Improve controls based on incidents and lessons learned.


Policy vs. Process vs. Evidence

TypeExample
PolicyOrganizational devices shall be protected against malware
ProcessIT monitors endpoint protection status
StandardSupported devices must run approved endpoint protection
ConfigurationEDR agent deployed and centrally managed
EvidenceEDR coverage report
RecordMalware incident investigation
TrainingEmployee malware-awareness training

The key is to demonstrate:

Requirement → Control → Monitoring → Response → Evidence


Cloud-First Startup Considerations

A cloud-native startup may not operate traditional physical servers.

Its malware-protection scope may instead include:

Employee Endpoints

  • Laptops
  • Desktops
  • Mobile devices

Development

  • Developer workstations
  • CI/CD runners
  • Build environments
  • Dependencies

Cloud

  • Virtual machines
  • Containers
  • Kubernetes workloads
  • Storage
  • Compute environments

SaaS

  • Email
  • Collaboration platforms
  • Business applications

The startup should determine appropriate protection based on its architecture and risk.


A.8.7 vs A.8.8 – Management of Technical Vulnerabilities

These controls are related but different.

ControlFocus
A.8.7Protection against malware
A.8.8Identification and management of technical vulnerabilities

Example

Installing EDR:

A.8.7

Patching an operating-system vulnerability:

A.8.8

Both may reduce malware risk.


A.8.7 vs A.8.1 – User Endpoint Devices

ControlFocus
A.8.1Security of endpoint devices
A.8.7Protection specifically against malware

A.8.1 establishes broader endpoint-security requirements.

A.8.7 focuses specifically on malware protection.


A.8.7 vs A.8.2 – Privileged Access Rights

ControlFocus
A.8.2Control privileged access
A.8.7Protect against malware

Restricting administrator privileges can reduce malware impact, but it does not replace malware protection.


A.8.7 vs A.7.10 – Storage Media

ControlFocus
A.7.10Security of storage media
A.8.7Protection against malware

USB devices are a good example where both controls may apply.


Questions an Auditor May Ask

1. How do you protect endpoints against malware?

Demonstrate the organization’s endpoint-security controls.

2. How do you know endpoint protection is active?

Show management-console or coverage reports.

3. How are malware events detected?

Explain EDR, antivirus, email-security, or other monitoring.

4. What happens when malware is detected?

Demonstrate the incident-response process.

5. How do you protect against ransomware?

Explain layered controls such as endpoint protection, patching, access restrictions, backups, and incident response.

6. How do employees report suspicious files?

Show the reporting procedure.

7. How do you protect remote workers?

Explain endpoint, authentication, patching, and remote-working controls.

8. How do you control software installation?

Demonstrate endpoint or administrative controls.

9. How do you protect cloud workloads?

Explain the controls relevant to the organization’s cloud architecture.

10. How do you learn from malware incidents?

Show incident reviews and improvement actions.


Useful Resources

Organizations implementing Annex A 8.7 may maintain:

  1. Malware Protection Policy – [Insert Draft Document Link]
  2. Endpoint Security Policy – [Insert Draft Document Link]
  3. Anti-Malware Procedure – [Insert Draft Document Link]
  4. Endpoint Protection Standard – [Insert Draft Document Link]
  5. Malware Incident Response Procedure – [Insert Draft Document Link]
  6. Malware Risk Assessment – [Insert Draft Document Link]
  7. Endpoint Protection Coverage Register – [Insert Draft Document Link]
  8. Malware Incident Report Template – [Insert Draft Document Link]
  9. Malware Protection Review Checklist – [Insert Draft Document Link]
  10. Employee Malware Awareness Guide – [Insert Draft Document Link]

Startup-Focused Quick Summary

For a startup, start with the basics:

Protect endpoints

Deploy appropriate endpoint security.

Keep systems updated

Patch operating systems and applications.

Use MFA

Reduce the impact of stolen credentials.

Restrict administrator access

Do not give users unnecessary privileges.

Secure email

Reduce malicious attachments and phishing.

Control software

Limit unauthorized applications and tools.

Protect removable media

Address USB and external-media risks.

Monitor

Detect malware and suspicious behavior.

Respond

Know how to isolate and investigate infected systems.

Train employees

Make reporting easy.

Maintain backups

Ensure important information can be recovered following destructive malware such as ransomware.


Startup-Focused Final Takeaway

ISO 27001 Annex A 8.7 is not simply:

“Install antivirus.”

It is about establishing a reasonable, risk-based capability to prevent, detect, respond to, and recover from malware.

A practical startup model is:

Assess → Prevent → Protect → Detect → Respond → Recover → Learn

For a SaaS startup, this could mean:

Managed endpoint protection + patching + MFA + restricted privileges + email security + software controls + monitoring + employee awareness + incident response + reliable backups.

The key question for an auditor is:

“How does your organization prevent malware, detect it when it occurs, respond to it, and recover from its effects?”

If the organization can demonstrate the complete lifecycle rather than simply showing an antivirus license, it has a much stronger implementation of Annex A 8.7.

One-Line Summary

ISO 27001 Annex A 8.7 ensures that organizations implement appropriate measures to prevent, detect, respond to, and recover from malware affecting information and associated assets.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *