A.8.7 Protection Against Malware
Control Objective
Protection against malware shall be implemented and supported by appropriate user awareness.
Policy Statement
anDREa implements a multi-layered defense strategy to protect its infrastructure, cloud environments, and endpoint devices against malicious software. This framework combines real-time automated detection, rigid data-locality constraints, incident response planning, and mandatory, recurring workforce security training.
Anti-Malware Control Framework
Our defense-in-depth model isolates and mitigates malware vectors across three primary domains:
1. Endpoint Protection & Architecture
- Managed Chromebook Enforcers: For general corporate, operational, and office workflows, anDREa strongly encourages and provisions cloud-native Chromebooks. The inherent sandboxing and read-only system architecture of ChromeOS significantly reduce the local execution surface for malware.
- Endpoint Protection Tools: For development and engineering personnel utilizing Windows or Linux environments, active endpoint security software (e.g., Windows Defender) is mandatory. Technical baselines, configuration constraints, and update schedules are governed via A.06.07: Remote Working.
2. Cloud Infrastructure Monitoring (Microsoft Azure)
- Real-Time Telemetry: Subscriptions, resource groups, storage accounts, and Virtual Machines (VMs) deployed within the myDRE cloud ecosystem are continuously monitored by Microsoft Defender for Cloud.
- Automated Alert Routing: When a malware signature, anomalous behavior, or suspicious process execution is detected, the platform triggers automated notifications. These alerts are routed instantly to the following operations channels for triage:
- The dedicated monitoring inbox:
security@andrea-cloud.com. - The centralized Issues and Risk Logging repository.
The legacy "Security-related incidents department" queue within the ticketing system has been phased out in favor of these unified streams.
3. Human Awareness & Education
- Mandatory Training Lifecycle: Technical controls are paired with continuous workforce education. Malware detection, phishing indicators, and safe downloading habits are core components of the Information Security & Data Protection Training.
- Frequency: This curriculum must be successfully completed by all personnel upon onboarding and formally renewed annually thereafter (see A.06.02 - Terms and conditions of employment and A.06.03 - Information security awareness, education and training).
Incident Response and Containment
In the event that an active malware infection bypasses preventive barriers, the response, containment, and system restoration workflows are executed strictly in accordance with the formalized Disaster Recovery Plan.