N.4.04 Malware Control and Prevention
Control Overview
This control mandates that the organization implements robust, proactive defenses to detect, neutralize, and prevent the execution of malicious software (malware, ransomware, spyware) across its network and information systems. To prevent malware from compromising the availability, integrity, or confidentiality of corporate or client data, anti-malware measures must combine technical controls—such as endpoint detection, email filtering, and automated threat updates—with organizational guardrails like continuous user awareness training.
Applicability Note: This control is fully applicable to the anDREa platform and governs malware prevention across all corporate communication suites, engineering endpoints, and cloud environments.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, relying on multi-layered technical filtering to neutralize malicious code before it reaches our environment.
Rather than relying on a single defensive layer, anDREa deploys anti-malware protection across our entire operational architecture. At the endpoint layer, all company-issued devices enforce native anti-malware baselines (e.g., Windows Defender) with automated signature and configuration updates. At the ingestion layer, both our Google Workspace (business operations) and Microsoft Office 365 (platform delivery) environments utilize advanced, cloud-native spam, phishing, and malware sandbox filtering. This automated protection is reinforced by classification-based data encryption and mandatory security awareness training for all staff, ensuring that email-borne or web-delivered threat vectors are consistently caught and managed.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.08.07 - Protection against malware | Mandates that protection against malware is implemented and supported by appropriate user awareness, configuration baselines, and detection systems. |
| Ingestion Defense | Google Security Advisor Configurations | Operational system baselines proving live email threat filtering, link scanning, and attachment sandboxing within corporate communication channels. (Google Security Advisor) |
| Infrastructure Protection | Office 365 Cloud Security Baselines | Active security configurations governing anti-malware policies across the platform infrastructure delivery layer. |
| Operational Governance | Monthly CTO Security Reports | Formal technical audit records demonstrating continuous oversight, incident metrics, and explicit confirmation of malware control health. |
| Staff Competency | Security Awareness Curricula & Logs | Documentation of role-based training modules testing and verifying staff capability to identify phishing, social engineering, and malicious links. (Training) |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Multi-layered endpoint and ingestion filtering, automated cloud-native sandboxing, and monthly executive validation loops are fully operationalized and traceably logged.