Cyber Insurance Subjectivity Tracker

Controls / Other controls proposal forms ask about

Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: run centrally managed, behaviour-based anti-malware on every workstation and server.

In Australia

No Essential Eight requirement covers this control; in Australia it is on the schedule as a condition beyond the core list.

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 5.2.1
PCI DSS v4.0.1 (add-on)
Anti-malware deployed on all system components

An anti-malware solution (one or more) must be installed on every system component, with the only exception being components that the periodic evaluations under Requirement 5.2.3 have concluded are not at risk from malware. A component counts as affected by malware when real-world active exploits exist for it, not merely theoretical ones. Applicability: applies to every entity in scope, with no special notes. Customized approach objective: automated mechanisms stop systems from turning into a route for malware attacks.

evidence an assessor asks for System component inventory reconciled against the anti-malware console's list of protected hosts; Deployment status report showing agent installed and healthy per system component; List of excluded components with a reference to the 5.2.3 evaluation for each; Sample screenshots or agent queries from selected servers and workstations showing the solution running

PCI DSS 5.3.1
PCI DSS v4.0.1 (add-on)
Anti-malware kept current through automatic updates

The anti-malware solution or solutions must be kept up to date by means of automatic updates, covering signatures, security updates, threat analysis engines and any other protections the solution relies on. Updates should come from a trusted source as soon as they are available; they may be pulled first to a central location, for example for testing, before rollout to individual components. Applicability: applies to every entity in scope, with no special notes. Objective under the customized approach: anti-malware mechanisms are able to detect and deal with the newest malware threats.

evidence an assessor asks for Management console or master installation policy showing automatic update settings; Report of signature and engine versions across endpoints and servers; Update logs showing timely distribution after vendor releases; Sample of individual hosts with current definition dates

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 10.1
CIS Controls v8.1
Deploy and Maintain Anti-Malware Software

Install and keep anti-malware software running on every enterprise asset.

evidence an assessor asks for Anti-malware console deployment report showing agent coverage against the full asset inventory, with unprotected assets listed; Exception register for assets that cannot run anti-malware, with the compensating control and approver for each; Endpoint security standard requiring the anti-malware agent on every workstation, server and mobile device class, and naming the approved product; Agent health report listing endpoints with the service stopped, tamper protection off or no check-in within the last 7 days; Reconciliation of the anti-malware console against the asset inventory and new-build tickets, showing agents installed at provisioning

CIS 10.6
CIS Controls v8.1

Centrally manage anti-malware software.

evidence an assessor asks for Reconciliation of the asset inventory against console-registered endpoints, listing unmanaged devices and the date each was enrolled; Malware defence standard naming the central console as the only approved management point and the owner accountable for policy changes; Central anti-malware console showing all endpoints registered, policy assignment by group and the administrators with console rights; Console audit log of policy changes, exclusions added and detections reviewed, with who made each change

CIS 10.7
CIS Controls v8.1

Use behavior-based anti-malware software.

evidence an assessor asks for Endpoint coverage report listing every device running the behaviour-based engine, reconciled to the enterprise asset inventory; Endpoint protection standard stating behavioural detection must run in block mode, with the approval route for any detect-only exception; Product configuration showing behaviour-based detection, such as heuristics, machine learning or EDR behavioural rules, enabled and in block mode; Sample of detections raised by behaviour rules rather than signatures, with the analyst disposition

DE.CM-09
NIST CSF 2.0

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

evidence an assessor asks for EDR coverage report by asset class; File integrity monitoring baseline and drift alerts; Software inventory reconciliation with allowlist; Hardware tamper detection telemetry; Patch and configuration drift dashboard

HIPAA Security Rule, when it applies

HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.

ClauseThe held text, and the evidence an assessor asks for
164.308(a)(5)(ii)(B)
HIPAA Security Rule (add-on)
Protection from Malicious Software (Addressable)

Implement procedures for guarding against, detecting, and reporting malicious software. NIST recommends endpoint protection, email filtering, web filtering, and user reporting channels.

evidence an assessor asks for Endpoint protection deployment report; Email gateway configuration; Malware incident records; User reporting procedure

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 5.2.1
PCI DSS v4.0.1 (add-on)
Anti-malware deployed on all system components

An anti-malware solution (one or more) must be installed on every system component, with the only exception being components that the periodic evaluations under Requirement 5.2.3 have concluded are not at risk from malware. A component counts as affected by malware when real-world active exploits exist for it, not merely theoretical ones. Applicability: applies to every entity in scope, with no special notes. Customized approach objective: automated mechanisms stop systems from turning into a route for malware attacks.

evidence an assessor asks for System component inventory reconciled against the anti-malware console's list of protected hosts; Deployment status report showing agent installed and healthy per system component; List of excluded components with a reference to the 5.2.3 evaluation for each; Sample screenshots or agent queries from selected servers and workstations showing the solution running

PCI DSS 5.3.1
PCI DSS v4.0.1 (add-on)
Anti-malware kept current through automatic updates

The anti-malware solution or solutions must be kept up to date by means of automatic updates, covering signatures, security updates, threat analysis engines and any other protections the solution relies on. Updates should come from a trusted source as soon as they are available; they may be pulled first to a central location, for example for testing, before rollout to individual components. Applicability: applies to every entity in scope, with no special notes. Objective under the customized approach: anti-malware mechanisms are able to detect and deal with the newest malware threats.

evidence an assessor asks for Management console or master installation policy showing automatic update settings; Report of signature and engine versions across endpoints and servers; Update logs showing timely distribution after vendor releases; Sample of individual hosts with current definition dates

In United Kingdom

ClauseThe held text, and the evidence an assessor asks for
CE-MP.1
Cyber Essentials
Anti-Malware Software Deployed

Implement anti-malware on all in-scope devices: anti-malware software (signature/heuristic), application allowlisting, or sandboxing of untrusted code.

evidence an assessor asks for AV/EDR console inventory vs asset list; coverage percentage report

CE-MP.2
Cyber Essentials
Anti-Malware Signatures Updated

Where anti-malware software is used, it must be kept up to date with the latest signatures and engine updates.

evidence an assessor asks for AV signature age report; out-of-date device list with remediation

CE-MP.3
Cyber Essentials
Anti-Malware Scans Files on Access and Web Pages

Anti-malware software must scan files automatically on access, scan web pages when accessed, and prevent connections to malicious websites.

evidence an assessor asks for on-access scan policy; web protection enabled screenshot; SafeBrowsing/SmartScreen evidence

PCI DSS v4.0.1, when it applies

Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.

ClauseThe held text, and the evidence an assessor asks for
PCI DSS 5.2.1
PCI DSS v4.0.1 (add-on)
Anti-malware deployed on all system components

An anti-malware solution (one or more) must be installed on every system component, with the only exception being components that the periodic evaluations under Requirement 5.2.3 have concluded are not at risk from malware. A component counts as affected by malware when real-world active exploits exist for it, not merely theoretical ones. Applicability: applies to every entity in scope, with no special notes. Customized approach objective: automated mechanisms stop systems from turning into a route for malware attacks.

evidence an assessor asks for System component inventory reconciled against the anti-malware console's list of protected hosts; Deployment status report showing agent installed and healthy per system component; List of excluded components with a reference to the 5.2.3 evaluation for each; Sample screenshots or agent queries from selected servers and workstations showing the solution running

PCI DSS 5.3.1
PCI DSS v4.0.1 (add-on)
Anti-malware kept current through automatic updates

The anti-malware solution or solutions must be kept up to date by means of automatic updates, covering signatures, security updates, threat analysis engines and any other protections the solution relies on. Updates should come from a trusted source as soon as they are available; they may be pulled first to a central location, for example for testing, before rollout to individual components. Applicability: applies to every entity in scope, with no special notes. Objective under the customized approach: anti-malware mechanisms are able to detect and deal with the newest malware threats.

evidence an assessor asks for Management console or master installation policy showing automatic update settings; Report of signature and engine versions across endpoints and servers; Update logs showing timely distribution after vendor releases; Sample of individual hosts with current definition dates

Also cited: ISO/IEC 27001:2022 Annex A

A lens in any jurisdiction, never a gap on its own.

ClauseThe held text, and the evidence an assessor asks for
A.8.7
ISO/IEC 27001:2022 (lens)
Protection against malware

Malware protection is to be implemented and backed by appropriate user awareness. Purpose (stated in ISO/IEC 27002:2022): ensures information and associated assets are protected against malware. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.7.

evidence an assessor asks for Statement of Applicability entry for control A.8.7, showing inclusion or justified exclusion, implementation status and the risks it treats; Anti-malware deployment and update status reports across endpoints, servers and gateways; Application allowlisting and malicious website blocking configurations; Email, download and web scanning configuration at gateways and endpoints, including handling of encrypted content; Approved exception records for disabled protections with justification, approver and review date

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule