UNCLASSIFIED 5.8 Malicious Code Protection Malicious code such as such as viruses, worms, spyware and Trojan Horses are popular attack vectors for a range of threat actors seeking to gain unauthorised access to sensitive ICT systems and the information they store and handle. The threat actors use e-mail attachments, infected websites, instant messages, chat rooms and social media to trick users into clicking on infected links. Malicious code exploits vulnerabilities in ICT hardware and applications to breach security. Therefore, understanding malicious code risks and applying appropriate security countermeasures can achieve the mandated minimum-security outcomes below. IS7 – All organisations with critical infrastructure must apply appropriate controls against malicious code. As a minimum requirement, the organisations must: (a) assess the risk of malicious code; (b) adopt a malicious code policy that considers their business needs and threat environment; (c) deploy suitable malicious code detection mechanisms; (d) educate users about malicious code risks; (e) ensure that authorised mobile code complies with security policy; and (f) address published technical vulnerabilities in a timely manner. To achieve the security outcomes mandated above, organisations must:  Mandate that all users, regardless of location, abide by a malicious code policy that should, amongst other issues, require the installation of anti-virus or anti-malware software on all devices; update of anti-virus or anti-malware software signatures; system scanning; secure file attachment handling; secure file sharing; removable media scans; virus log generation and review;  Identify and block all direct e.g. e-mail attachments, social media, malicious websites and indirect e.g. unauthorised personal laptops, PDA, USB, CD/DVD routes that threat actors could use to inject malicious code;  Ensure that network boundary devices have the capacity to check inbound and outbound content for malicious code such as viruses, worms and Trojan horses and mobile code such as Java, JavaScript, ActiveX, or any other executable code with potential to damage networks, applications, and data;  Use measures such as logically segregated environments (i.e. sandboxes) and application-specific controls to manage the execution of mobile code;  Install host-based software to scan, clean, quarantine and raise alerts about suspicious files, including malicious websites, prior to access;  Provide users suitable security awareness and education about the impacts, preventative measures and actions against malicious code attacks;  Routinely patch ICT systems, security enforcing products and applications against known vulnerabilities to reduce exposure to malicious code;  Conduct regular vulnerability assessments to identify potential weaknesses that could enable the introduction of malicious code;  Build adequate capacity to identify, deter, resist and defend against known and unknown (zero-day) malicious code attacks; and 29

Select target paragraph3