What is ISO 27001 Annex A 8.7 – Protection Against Malware?
ISO 27001 Annex A 8.7 focuses on implementing appropriate measures to protect information and associated assets against malware.
Malware is malicious software designed to damage systems, disrupt operations, steal information, gain unauthorized access, or perform other unauthorized activities.
Examples include:
- Viruses
- Worms
- Trojans
- Ransomware
- Spyware
- Keyloggers
- Rootkits
- Botnet malware
- Cryptominers
- Remote-access malware
- Malicious scripts
- Fileless malware
- Malicious macros
- Other unwanted or harmful software
Simple Explanation
Prevent malware from entering your environment, detect it when it does, respond quickly, and reduce the chance of it spreading.
For a modern startup, malware protection is not limited to installing antivirus software.
A practical malware-defense strategy may include:
Endpoint protection + patching + email security + web protection + application controls + user awareness + monitoring + incident response
Why is Protection Against Malware Important?
Malware can enter an organization through many different routes.
For example:
Phishing Email
↓
Malicious Attachment
↓
Employee Opens File
↓
Malware Executes
↓
Credential Theft
↓
Lateral Movement
↓
Data Access / Encryption
Malware can affect:
- Laptops
- Desktops
- Servers
- Mobile devices
- Cloud workloads
- Virtual machines
- Containers
- Applications
- Email systems
- File shares
- Removable media
Common Malware Risks
- Ransomware
- Credential theft
- Data theft
- Unauthorized remote access
- Business disruption
- Data encryption
- Destruction of information
- System compromise
- Financial loss
- Reputational damage
- Customer impact
Simple Principle
Malware protection should be a layered process, not a single antivirus installation.
What Does ISO 27001 Annex A 8.7 Require?
The organization should implement appropriate measures to protect against malware.
The exact controls should be determined based on:
- Risk assessment
- Technology environment
- Types of devices
- Information sensitivity
- Threat environment
- Remote working
- Cloud usage
- Business requirements
- Regulatory requirements
- Customer requirements
A small SaaS startup does not necessarily need the same malware-security architecture as a large bank.
However, it should be able to demonstrate that it has considered malware risks and implemented reasonable controls.
What is Malware Protection?
Malware protection consists of multiple layers.
Prevention
Stop malware from entering or executing.
Detection
Identify suspicious or malicious activity.
Response
Contain and remove the threat.
Recovery
Restore affected systems and information.
A simple model is:
Prevent → Detect → Contain → Remove → Recover → Learn
Activities Required to Implement Annex A 8.7
1. Identify Where Malware Could Affect the Organization
Start by identifying assets that could be exposed to malware.
Examples:
- Employee laptops
- Desktops
- Servers
- Cloud workloads
- Mobile devices
- File storage
- SaaS applications
- Development environments
- CI/CD systems
- Removable media
2. Deploy Endpoint Protection
Organizations should implement appropriate endpoint protection.
Depending on risk, this could include:
- Antivirus
- Endpoint Detection and Response (EDR)
- Endpoint protection platforms
- Host-based security controls
- Application control
- Device security management
For example:
Company Laptop
↓
Endpoint Protection
↓
Malware Detection
↓
Alert
↓
Security Team
↓
Investigation / Isolation
For higher-risk environments, EDR may provide capabilities beyond traditional antivirus.
3. Keep Systems Updated
Malware frequently exploits known vulnerabilities.
Therefore, malware protection should be connected with:
A.8.8 – Management of Technical Vulnerabilities
Important updates may include:
- Operating-system patches
- Browser updates
- Application updates
- Security-agent updates
- Firmware updates
- Server updates
- Third-party software updates
A device with malware protection but a severely outdated operating system can still present significant risk.
4. Protect Email
Email is a common malware-delivery channel.
Organizations should consider controls such as:
- Spam filtering
- Malware scanning
- Attachment scanning
- URL protection
- Phishing protection
- Domain protection
- Sender authentication
- Quarantine mechanisms
Users should be educated about suspicious:
- Attachments
- Links
- Login pages
- Executable files
- Office documents
- Unexpected invoices
- Password-reset requests
5. Control Malicious Attachments
Potentially dangerous file types may require additional controls.
Examples include:
- Executables
- Scripts
- Macro-enabled documents
- Compressed archives
- Disk images
The organization should determine appropriate restrictions based on its environment and business requirements.
6. Control Software Installation
Users should not be allowed to install arbitrary software on business devices without appropriate authorization.
Risks include:
- Malware
- Unlicensed software
- Vulnerable software
- Malicious browser extensions
- Unapproved remote-access tools
A startup may use:
- Standard software lists
- Application allowlisting where appropriate
- Endpoint management
- User restrictions
- Software-installation approval
7. Restrict Administrative Privileges
Malware can have a greater impact when executed by an administrator.
For example:
Standard User
↓
Malware Execution
↓
Limited Permissions
versus:
Administrator
↓
Malware Execution
↓
High Privileges
↓
Greater System Impact
This connects A.8.7 with A.8.2 – Privileged Access Rights.
Users should not have unnecessary administrator privileges.
8. Protect Removable Media
USB drives and other removable media can introduce malware.
Controls may include:
- Restricting unauthorized USB devices
- Scanning removable media
- Disabling unnecessary removable-media access
- Encrypting sensitive removable media
- Authorizing business use
- Monitoring where appropriate
This also connects with A.7.10 – Storage Media.
9. Protect Web Browsing
Websites can deliver malware through:
- Malicious downloads
- Drive-by attacks
- Malicious advertisements
- Fake software updates
- Browser exploits
- Phishing pages
Organizations may use:
- Secure DNS
- Web filtering
- Browser security
- Endpoint protection
- URL reputation controls
- Download restrictions
The controls should be appropriate to the organization’s risk.
10. Protect Cloud Workloads
Cloud does not eliminate malware risk.
Malware may affect:
- Virtual machines
- Containers
- Kubernetes workloads
- Build environments
- Developer systems
- Cloud-hosted applications
Organizations should determine which malware controls are appropriate for their cloud architecture.
For example:
Endpoint protection may be highly relevant for employee laptops, while workload security and image scanning may be more relevant for cloud workloads.
11. Protect Development Environments
Software-development environments can also be targeted.
Potential risks include:
- Malicious packages
- Compromised dependencies
- Malicious code
- Infected developer systems
- Compromised CI/CD tools
- Malicious scripts
Therefore, malware protection should be considered alongside:
- Secure coding
- Dependency management
- Vulnerability scanning
- Source-code security
- CI/CD security
12. Detect Malware
Detection mechanisms may include:
- Antivirus alerts
- EDR alerts
- SIEM alerts
- Email-security alerts
- Cloud-security alerts
- File-integrity monitoring
- Suspicious process detection
- Threat-intelligence indicators
The organization should determine which events require investigation.
13. Respond to Malware Incidents
A malware incident should have a defined response process.
For example:
Malware Detected
↓
Alert
↓
Investigate
↓
Isolate Device/System
↓
Contain Threat
↓
Remove Malware
↓
Reset Compromised Credentials
↓
Restore if Required
↓
Investigate Root Cause
↓
Lessons Learned
This connects with:
- A.5.24 – Incident Management Planning and Preparation
- A.5.25 – Assessment and Decision on Information Security Events
- A.5.26 – Response to Information Security Incidents
- A.5.27 – Learning from Information Security Incidents
14. Educate Employees
Technology alone cannot eliminate malware risk.
Employees should understand:
- Phishing
- Malicious attachments
- Suspicious links
- Fake login pages
- USB risks
- Software downloads
- Social engineering
- Reporting procedures
Training should explain what employees should do, not simply tell them:
“Do not click suspicious links.”
For example:
“If you accidentally open a suspicious attachment, disconnect from the network if instructed by your incident procedure and immediately report the event to IT/security.”
15. Define Malware Reporting
Employees should have a simple way to report:
- Suspicious emails
- Malware alerts
- Unexpected pop-ups
- Unknown software
- Unusual device behavior
- Suspicious browser activity
- Lost or compromised devices
This connects with A.6.8 – Information Security Event Reporting.
16. Maintain Malware Protection
Security tools should themselves remain operational.
Consider:
- Agent health
- Signature/update status
- EDR connectivity
- Policy configuration
- License status
- Coverage
- Unsupported devices
- Disabled protection
- Exceptions
An antivirus product installed six months ago but no longer updating is not effective protection.
Startup Example
Example: 50-Person SaaS Startup
The startup has:
- Windows laptops
- MacBooks
- Mobile devices
- AWS workloads
- GitHub
- Google Workspace
- Slack
- CRM
- CI/CD
Initially, the company relies only on basic antivirus.
Identified Risks
- Phishing
- Malicious attachments
- Browser-based malware
- Unapproved software
- Compromised developer laptops
- USB malware
- Cloud workload compromise
Improved Model
The startup implements:
Managed endpoint protection
↓
Automatic security updates
↓
MFA
↓
Restricted local administrator privileges
↓
Email malware/phishing protection
↓
Software-installation controls
↓
Employee security awareness
↓
Malware reporting
↓
EDR/security monitoring
↓
Incident response
This provides a layered approach without requiring a large security team.
Malware Protection Matrix
| Threat | Preventive Control | Detection | Response |
|---|---|---|---|
| Ransomware | EDR, patching, restricted privileges | EDR alerts | Isolate device |
| Phishing attachment | Email filtering | Email/security alert | Investigate |
| Malicious download | Web protection | Endpoint detection | Block/isolate |
| USB malware | USB controls/scanning | Endpoint detection | Remove/isolate |
| Malicious software | Application controls | EDR | Uninstall/block |
| Cloud workload malware | Workload security | Cloud monitoring | Isolate workload |
| Compromised developer device | EDR + patching | Security monitoring | Isolate/reset credentials |
Malware Protection Register
A simple register could contain:
| Asset/Area | Protection | Status | Owner | Review |
|---|---|---|---|---|
| Employee Laptops | EDR | Active | IT | Monthly |
| Mac Devices | Endpoint Security | Active | IT | Monthly |
| Windows Devices | EDR | Active | IT | Monthly |
| Malware Filtering | Active | IT | Monthly | |
| Cloud Workloads | Appropriate Workload Controls | Active | DevOps | Monthly |
| USB | Restricted/Controlled | Active | IT | Quarterly |
| Servers | Endpoint/Workload Protection | Active | DevOps | Monthly |
Malware Incident Example
Suppose an employee opens a malicious attachment.
The endpoint security system detects suspicious behavior.
Response
Malware Alert
↓
Security Investigation
↓
Endpoint Isolated
↓
User Notified
↓
Malware Removed
↓
Credentials Reviewed/Reset
↓
Logs Investigated
↓
Other Systems Checked
↓
Endpoint Restored
↓
Incident Closed
↓
Lessons Learned
The incident should be recorded according to the organization’s incident-management process.
What Evidence Can an Auditor Ask For?
An auditor may request:
Policies
- Malware Protection Policy
- Endpoint Security Policy
- Acceptable Use Policy
- Incident Management Policy
- Patch Management Procedure
Technical Evidence
- Endpoint protection deployment
- EDR dashboard
- Antivirus configuration
- Security-agent status
- Malware detection reports
- Email-security configuration
- Web-security configuration
Patch Evidence
- Patch reports
- Vulnerability reports
- Update status
- Exception records
Awareness Evidence
- Security awareness training
- Phishing awareness material
- Employee acknowledgements
- Training completion records
Incident Evidence
- Malware incidents
- Security alerts
- Investigation records
- Device-isolation records
- Lessons-learned records
Monitoring
- EDR alerts
- SIEM alerts
- Security monitoring records
ISO 27001 Annex A 8.7 Audit Checklist
| Question | Yes/No | Evidence |
|---|---|---|
| Has malware risk been assessed? | Risk assessment | |
| Are endpoints protected against malware? | EDR/AV dashboard | |
| Is protection centrally managed where appropriate? | Management console | |
| Are security agents operational and updated? | Agent status | |
| Are systems regularly patched? | Patch reports | |
| Is email malware protection implemented? | Email-security configuration | |
| Are malicious attachments appropriately controlled? | Email settings | |
| Is unauthorized software installation controlled? | Endpoint policy | |
| Are administrator privileges restricted? | Endpoint/user settings | |
| Are removable media risks addressed? | USB policy | |
| Are malware events monitored? | EDR/SIEM logs | |
| Is there a malware response procedure? | Incident procedure | |
| Are employees trained about malware risks? | Training records | |
| Can employees report suspected malware? | Reporting procedure | |
| Are malware incidents investigated? | Incident records | |
| Are malware controls periodically reviewed? | Review records |
Common Mistakes
1. Thinking Antivirus Alone Is Enough
Modern malware protection should be layered.
2. Ignoring Mac and Mobile Devices
Malware protection requirements should consider the organization’s actual endpoint environment rather than assuming only Windows devices matter.
3. No Central Visibility
If IT does not know whether security software is installed and operational, coverage gaps can remain unnoticed.
4. Ignoring Patch Management
Malware frequently exploits vulnerabilities.
Protection against malware should therefore connect with vulnerability management.
5. Allowing Everyone to Be Local Administrator
Excessive privileges can increase the impact of malware.
6. Ignoring Email
Email remains an important malware and phishing delivery channel.
7. Ignoring Cloud Workloads
Cloud infrastructure can also be compromised by malicious software, scripts, packages, or compromised credentials.
8. No Incident Response
Detecting malware is not enough.
The organization should know what happens after detection.
9. No User Reporting Process
Employees should know how and where to report suspected malware.
10. No Evidence of Effectiveness
Simply purchasing an endpoint-security product does not demonstrate that devices are actually protected.
Practical Startup Implementation Model
A startup can implement Annex A 8.7 using:
Assess → Prevent → Protect → Detect → Respond → Recover → Learn
Assess
Identify malware risks and affected assets.
Prevent
Reduce the chance of malware entering the environment.
Protect
Deploy endpoint, email, application, and other appropriate controls.
Detect
Monitor for malicious activity.
Respond
Contain and investigate malware incidents.
Recover
Restore affected devices and systems.
Learn
Improve controls based on incidents and lessons learned.
Policy vs. Process vs. Evidence
| Type | Example |
|---|---|
| Policy | Organizational devices shall be protected against malware |
| Process | IT monitors endpoint protection status |
| Standard | Supported devices must run approved endpoint protection |
| Configuration | EDR agent deployed and centrally managed |
| Evidence | EDR coverage report |
| Record | Malware incident investigation |
| Training | Employee malware-awareness training |
The key is to demonstrate:
Requirement → Control → Monitoring → Response → Evidence
Cloud-First Startup Considerations
A cloud-native startup may not operate traditional physical servers.
Its malware-protection scope may instead include:
Employee Endpoints
- Laptops
- Desktops
- Mobile devices
Development
- Developer workstations
- CI/CD runners
- Build environments
- Dependencies
Cloud
- Virtual machines
- Containers
- Kubernetes workloads
- Storage
- Compute environments
SaaS
- Collaboration platforms
- Business applications
The startup should determine appropriate protection based on its architecture and risk.
A.8.7 vs A.8.8 – Management of Technical Vulnerabilities
These controls are related but different.
| Control | Focus |
|---|---|
| A.8.7 | Protection against malware |
| A.8.8 | Identification and management of technical vulnerabilities |
Example
Installing EDR:
A.8.7
Patching an operating-system vulnerability:
A.8.8
Both may reduce malware risk.
A.8.7 vs A.8.1 – User Endpoint Devices
| Control | Focus |
|---|---|
| A.8.1 | Security of endpoint devices |
| A.8.7 | Protection specifically against malware |
A.8.1 establishes broader endpoint-security requirements.
A.8.7 focuses specifically on malware protection.
A.8.7 vs A.8.2 – Privileged Access Rights
| Control | Focus |
|---|---|
| A.8.2 | Control privileged access |
| A.8.7 | Protect against malware |
Restricting administrator privileges can reduce malware impact, but it does not replace malware protection.
A.8.7 vs A.7.10 – Storage Media
| Control | Focus |
|---|---|
| A.7.10 | Security of storage media |
| A.8.7 | Protection against malware |
USB devices are a good example where both controls may apply.
Questions an Auditor May Ask
1. How do you protect endpoints against malware?
Demonstrate the organization’s endpoint-security controls.
2. How do you know endpoint protection is active?
Show management-console or coverage reports.
3. How are malware events detected?
Explain EDR, antivirus, email-security, or other monitoring.
4. What happens when malware is detected?
Demonstrate the incident-response process.
5. How do you protect against ransomware?
Explain layered controls such as endpoint protection, patching, access restrictions, backups, and incident response.
6. How do employees report suspicious files?
Show the reporting procedure.
7. How do you protect remote workers?
Explain endpoint, authentication, patching, and remote-working controls.
8. How do you control software installation?
Demonstrate endpoint or administrative controls.
9. How do you protect cloud workloads?
Explain the controls relevant to the organization’s cloud architecture.
10. How do you learn from malware incidents?
Show incident reviews and improvement actions.
Useful Resources
Organizations implementing Annex A 8.7 may maintain:
- Malware Protection Policy – [Insert Draft Document Link]
- Endpoint Security Policy – [Insert Draft Document Link]
- Anti-Malware Procedure – [Insert Draft Document Link]
- Endpoint Protection Standard – [Insert Draft Document Link]
- Malware Incident Response Procedure – [Insert Draft Document Link]
- Malware Risk Assessment – [Insert Draft Document Link]
- Endpoint Protection Coverage Register – [Insert Draft Document Link]
- Malware Incident Report Template – [Insert Draft Document Link]
- Malware Protection Review Checklist – [Insert Draft Document Link]
- Employee Malware Awareness Guide – [Insert Draft Document Link]
Startup-Focused Quick Summary
For a startup, start with the basics:
Protect endpoints
Deploy appropriate endpoint security.
Keep systems updated
Patch operating systems and applications.
Use MFA
Reduce the impact of stolen credentials.
Restrict administrator access
Do not give users unnecessary privileges.
Secure email
Reduce malicious attachments and phishing.
Control software
Limit unauthorized applications and tools.
Protect removable media
Address USB and external-media risks.
Monitor
Detect malware and suspicious behavior.
Respond
Know how to isolate and investigate infected systems.
Train employees
Make reporting easy.
Maintain backups
Ensure important information can be recovered following destructive malware such as ransomware.
Startup-Focused Final Takeaway
ISO 27001 Annex A 8.7 is not simply:
“Install antivirus.”
It is about establishing a reasonable, risk-based capability to prevent, detect, respond to, and recover from malware.
A practical startup model is:
Assess → Prevent → Protect → Detect → Respond → Recover → Learn
For a SaaS startup, this could mean:
Managed endpoint protection + patching + MFA + restricted privileges + email security + software controls + monitoring + employee awareness + incident response + reliable backups.
The key question for an auditor is:
“How does your organization prevent malware, detect it when it occurs, respond to it, and recover from its effects?”
If the organization can demonstrate the complete lifecycle rather than simply showing an antivirus license, it has a much stronger implementation of Annex A 8.7.
One-Line Summary
ISO 27001 Annex A 8.7 ensures that organizations implement appropriate measures to prevent, detect, respond to, and recover from malware affecting information and associated assets.
