Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

N.4.04 Malware Control and Prevention

Control Overview

This control mandates that the organization implements robust, proactive defenses to detect, neutralize, and prevent the execution of malicious software (malware, ransomware, spyware) across its network and information systems. To prevent malware from compromising the availability, integrity, or confidentiality of corporate or client data, anti-malware measures must combine technical controls—such as endpoint detection, email filtering, and automated threat updates—with organizational guardrails like continuous user awareness training.

note

Applicability Note: This control is fully applicable to the anDREa platform and governs malware prevention across all corporate communication suites, engineering endpoints, and cloud environments.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, relying on multi-layered technical filtering to neutralize malicious code before it reaches our environment.

Rather than relying on a single defensive layer, anDREa deploys anti-malware protection across our entire operational architecture. At the endpoint layer, all company-issued devices enforce native anti-malware baselines (e.g., Windows Defender) with automated signature and configuration updates. At the ingestion layer, both our Google Workspace (business operations) and Microsoft Office 365 (platform delivery) environments utilize advanced, cloud-native spam, phishing, and malware sandbox filtering. This automated protection is reinforced by classification-based data encryption and mandatory security awareness training for all staff, ensuring that email-borne or web-delivered threat vectors are consistently caught and managed.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.07 - Protection against malwareMandates that protection against malware is implemented and supported by appropriate user awareness, configuration baselines, and detection systems.
Ingestion DefenseGoogle Security Advisor ConfigurationsOperational system baselines proving live email threat filtering, link scanning, and attachment sandboxing within corporate communication channels. (Google Security Advisor)
Infrastructure ProtectionOffice 365 Cloud Security BaselinesActive security configurations governing anti-malware policies across the platform infrastructure delivery layer.
Operational GovernanceMonthly CTO Security ReportsFormal technical audit records demonstrating continuous oversight, incident metrics, and explicit confirmation of malware control health.
Staff CompetencySecurity Awareness Curricula & LogsDocumentation of role-based training modules testing and verifying staff capability to identify phishing, social engineering, and malicious links. (Training)

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Multi-layered endpoint and ingestion filtering, automated cloud-native sandboxing, and monthly executive validation loops are fully operationalized and traceably logged.