GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

INF-009 Malware and Endpoint Protection

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Managed endpoints and production workloads are protected by anti-malware or endpoint detection and response tooling with up-to-date signatures or behavioural detection. Software firewalls are configured on managed endpoints. Unauthorised or user-installed software on production systems is prevented or detected. Inbound email is filtered for spam and phishing, and the filter's detection content is updated automatically at the interval the supplier defines.

Rationale

Endpoint protection and host-based controls are the last line of defence against a compromised endpoint or malicious code running in production. Email belongs with them because it is the route most of that code arrives by, and the filter is the one detection surface whose value collapses fastest without current content: a campaign is usually days old, so a filter updated weekly by hand is filtering last week's attacks. Automatic updates are the requirement rather than a convenience.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (24)

TVM-02Malware and Malicious Instructions Protection Policy and Proceduresfull
UEM-05Endpoint Managementfull
UEM-09Anti-Malware Detection and Preventionfull
UEM-10Software Firewallfull
TVM-02Malware and Malicious Instructions Protection Policy and Proceduresfull
UEM-05Endpoint Managementfull
UEM-09Anti-Malware Detection and Preventionfull
UEM-10Software Firewallfull
HIPAA-164.308.a.5.ii.BProtection from Malicious Softwarepartial
8.1User endpoint devicesinformative
8.19Installation of software on operational systemsfull
8.7Protection against malwarefull
NIS2-CIR-12.3Removable Media Policyinformative
NIS2-CIR-6.9Protection Against Malicious and Unauthorised Softwarefull
CM-11User-installed Softwarepartial
CM-7(2)Least Functionality | Prevent Program Executionpartial
CM-7(5)Least Functionality | Authorized Software — Allow-by-exceptionpartial
SC-18Mobile Codeinformative
SC-44Detonation Chambersinformative
SC-7(12)Boundary Protection | Host-based Protectionpartial
SI-3Malicious Code Protectionfull
SI-4(23)System Monitoring | Host-based Devicesfull
SI-8Spam Protectionpartial
SI-8(2)Spam Protection | Automatic Updatesfull

Evidence (3)

tool_outputtechnicalautomated

EDR or anti-malware management console report showing deployment coverage, signature/detection engine currency, and alert status across managed endpoints and production workloads.

Example: CrowdStrike Falcon, Microsoft Defender for Endpoint, or Sentinel One management console export showing agent deployment percentage, last signature update, and active alerts for production scope

Test: Export the EDR management console coverage report. Verify: (1) EDR or anti-malware agents are deployed on all managed endpoints and production workloads in scope; (2) signatures or detection models were updated within the vendor-defined maximum interval; (3) any endpoint with a gap in coverage has a documented remediation timeline; (4) host-based firewalls are shown as enabled on managed endpoints.

configurationtechnicalautomated

Software installation restriction policy configuration (e.g., allowlisting or MDM policy) preventing unauthorised software installation on production systems and managed endpoints.

Example: MDM (Jamf, Intune, or equivalent) software restriction policy configuration export or AWS Systems Manager Inventory report showing unapproved software detected on production instances

Test: Request the software restriction policy configuration export. Verify: (1) a policy is enforced that prevents or alerts on installation of unapproved software; (2) the policy covers all managed endpoints and production workloads; (3) any software installation alerts from the last 90 days have been reviewed and actioned.

configurationtechnicalautomated

Email filtering configuration showing spam and phishing detection in force across the organisation's inbound mail and the automatic update setting for its detection content.

Example: Mail security policy export, all accepted domains, 2026-08-21

Test: Export the email filtering configuration. Verify: (1) filtering is applied to every inbound mail domain the organisation accepts mail on, including aliases and parked domains, (2) the detection content's last update timestamp falls within the interval the supplier defines, (3) updates are applied automatically rather than by a scheduled manual task, (4) the filter is in enforcing mode rather than logging only, (5) an exclusion or allowlist entry in force carries a recorded justification and an expiry.

Questions (2)

boolean

Are managed endpoints and production workloads protected by anti-malware or endpoint detection and response tooling?

EDR deployment should cover all managed endpoints and, where applicable, production compute workloads. Behavioural detection (EDR) is preferred over signature-only anti-malware.

multi

Which endpoint and workload protection tooling is deployed across production systems and managed endpoints?

Endpoint detection and response agents on managed endpoints and production workloadsAnti-malware with signature updates, without behavioural detectionHost-based firewall enforced through device management or policySoftware allowlisting or application control policyDevice compliance checks enforced through device managementSpam and phishing filtering on inbound email with automatic detection content updatesNone of the above

Options run from the strongest coverage to the weakest. A modern detection and response agent across all managed endpoints plus host-based firewall enforcement is the minimum for a service provider. Email filtering belongs here because it is the route most malicious code arrives by, and its value collapses fastest without current detection content. Name capabilities rather than products when recording what is deployed.