UNCLASSIFIED
5.8
Malicious Code Protection
Malicious code such as such as viruses, worms, spyware and Trojan Horses are
popular attack vectors for a range of threat actors seeking to gain unauthorised
access to sensitive ICT systems and the information they store and handle. The
threat actors use e-mail attachments, infected websites, instant messages, chat
rooms and social media to trick users into clicking on infected links. Malicious
code exploits vulnerabilities in ICT hardware and applications to breach security.
Therefore, understanding malicious code risks and applying appropriate security
countermeasures can achieve the mandated minimum-security outcomes below.
IS7 – All organisations with critical infrastructure must apply appropriate
controls against malicious code. As a minimum requirement, the organisations
must: (a) assess the risk of malicious code; (b) adopt a malicious code policy
that considers their business needs and threat environment; (c) deploy suitable
malicious code detection mechanisms; (d) educate users about malicious code
risks; (e) ensure that authorised mobile code complies with security policy; and
(f) address published technical vulnerabilities in a timely manner.
To achieve the security outcomes mandated above, organisations must:
Mandate that all users, regardless of location, abide by a malicious code
policy that should, amongst other issues, require the installation of anti-virus
or anti-malware software on all devices; update of anti-virus or anti-malware
software signatures; system scanning; secure file attachment handling;
secure file sharing; removable media scans; virus log generation and review;
Identify and block all direct e.g. e-mail attachments, social media, malicious
websites and indirect e.g. unauthorised personal laptops, PDA, USB,
CD/DVD routes that threat actors could use to inject malicious code;
Ensure that network boundary devices have the capacity to check inbound
and outbound content for malicious code such as viruses, worms and Trojan
horses and mobile code such as Java, JavaScript, ActiveX, or any other
executable code with potential to damage networks, applications, and data;
Use measures such as logically segregated environments (i.e. sandboxes)
and application-specific controls to manage the execution of mobile code;
Install host-based software to scan, clean, quarantine and raise alerts about
suspicious files, including malicious websites, prior to access;
Provide users suitable security awareness and education about the impacts,
preventative measures and actions against malicious code attacks;
Routinely patch ICT systems, security enforcing products and applications
against known vulnerabilities to reduce exposure to malicious code;
Conduct regular vulnerability assessments to identify potential weaknesses
that could enable the introduction of malicious code;
Build adequate capacity to identify, deter, resist and defend against known
and unknown (zero-day) malicious code attacks; and
29