Compliance Framework Alignment
ISO/IEC 27001:2022 — A.8.1 (User endpoint devices) ISO/IEC 27001:2022 — A.8.7 (Protection against malware) This document is a configurable policy template intended to help you structure endpoint and anti-malware controls against the referenced frameworks. It is not legal, audit, or compliance advice, and generating it does not by itself make your organisation compliant — you remain responsible for implementing, evidencing, and independently assessing the controls.
ACME TECHNOLOGIES PVT LTD ENDPOINT & ANTI-MALWARE POLICY
Effective Date [Effective Date]
Policy Owner Chief Information Security Officer
Classification Internal
Review Cycle At least annually 1. Purpose and Scope
This policy sets out how Acme Technologies Pvt Ltd secures user endpoint devices and protects its systems and information against malicious software. It applies to all endpoints that store, process, or access organisational information — including laptops, desktops, servers acting as workstations, tablets, and smartphones — whether corporate-owned or, where expressly permitted, personally owned. It applies to all employees, contractors, interns, and third parties who operate such devices. The controls in this policy give effect to ISO/IEC 27001:2022 Annex A control 8.1 (user endpoint devices) and 8.7 (protection against malware), and, where applicable, to the corresponding Trust Services Criteria and PCI DSS requirements identified above.
2. Endpoint Hardening Baseline
Every managed endpoint must be configured to a documented secure baseline before it is issued and must remain in conformance thereafter. The baseline is derived from a recognised hardening standard (for example, the CIS Benchmarks or vendor security baselines) for each operating system in use. At minimum, the baseline (a) removes or disables default and unnecessary accounts, services, and ports; (b) enforces least-privilege — standard users do not hold local administrator rights; (c) enables the host firewall in a default-deny posture; (d) disables auto-run/auto-play for external media; and (e) applies the organisation's authentication controls. Configuration drift is detected through automated compliance monitoring, and deviations are remediated or formally risk-accepted by the Chief Information Security Officer .
3. Anti-Malware and Endpoint Detection & Response (EDR)
An approved endpoint protection solution (e.g. CrowdStrike Falcon, Microsoft Defender for Endpoint ) must be installed, active, and centrally managed on all endpoints for which such protection is technically feasible. The solution must provide real-time (on-access) protection together with behavioural detection, and must be configured so that end users cannot disable, alter, or uninstall it. Detections are reported to a central console, triaged, and — where warranted — isolated and investigated. This gives effect to ISO/IEC 27001:2022 A.8.7 and, where in scope, SOC 2 CC6.8 (preventing or detecting the introduction of unauthorised or malicious software) and PCI DSS v4.0.1 Requirements 5.2 and 5.3, which require anti-malware mechanisms to be deployed, active, maintained, and monitored.
4. Signature/Engine Updates and Scanning
Anti-malware definitions, engines, and cloud detection content must be kept current through automatic updates, consistent with PCI DSS v4.0.1 Requirement 5.3.1. In addition to continuous real-time analysis, endpoints must undergo scheduled scans; for systems within the PCI cardholder data environment (CDE), the scan approach (periodic scans plus real-time protection, or continuous behavioural analysis) and any periodic-scan frequency must be defined and justified by a documented targeted risk analysis under PCI DSS Requirement 5.3.2/5.3.2.1. Removable electronic media must be automatically scanned, or otherwise access-controlled, when inserted, connected, or mounted, per PCI DSS Requirement 5.3.3. Anti-malware audit logs are enabled and retained in line with the organisation's logging standard (for CDE systems, retention aligned to PCI DSS Requirement 5.3.4, i.e. at least twelve months, with the most recent ninety days readily available for analysis).
5. Systems Considered Not at Risk of Malware
Where a class of system component is assessed as not commonly affected by malicious software and is therefore not covered by an anti-malware solution, Acme Technologies Pvt Ltd maintains a documented list of those components and the supporting rationale. This list, and the evolving malware threat landscape affecting those components, is re-evaluated on a defined schedule set by a targeted risk analysis and, for PCI-scoped systems, at least once every six months, in line with PCI DSS v4.0.1 Requirements 5.2.3 and 5.2.3.1. If the assessment changes, anti-malware protection is deployed to the affected components.
6. Full-Disk Encryption
All portable endpoints — laptops, tablets, and smartphones — and any fixed endpoint that stores organisational information must have full-disk (or equivalent volume-level) encryption enabled using a platform-standard, industry-accepted algorithm (for example, AES-256 via BitLocker, FileVault, LUKS, or native mobile encryption). Recovery keys are escrowed centrally and protected against unauthorised access. Encryption status is monitored, and a device that reports as unencrypted is treated as non-compliant and remediated. This control supports ISO/IEC 27001:2022 A.8.1, which requires information stored on or accessible from endpoint devices to be protected, including through encryption of storage media.
7. Endpoint Patch Management and SLAs
Operating systems, firmware, and installed applications on endpoints must be kept up to date. Patches are deployed through a managed process on a risk-prioritised basis: critical-severity security patches are applied within 14 calendar days of vendor release, and all remaining applicable patches within a defined, documented window (typically thirty to ninety days) based on risk. For endpoints within the PCI cardholder data environment, critical and applicable security patches are installed within one month of release, consistent with PCI DSS v4.0.1 Requirement 6.3.3. Where a patch cannot be applied within its SLA, a documented compensating control and risk acceptance is recorded. Patch and configuration change monitoring also supports the detection of newly introduced vulnerabilities required by SOC 2 CC7.1.
8. Mobile Device Management (MDM) and BYOD
Mobile endpoints that access organisational information are enrolled in the organisation's Mobile Device Management platform, which enforces the security baseline and provides the ability to remotely locate, lock, and wipe a device. Personal (BYOD) devices may be used only for low-sensitivity functions (for example, calendar and email) and only when enrolled in the organisation's Mobile Device Management (MDM) platform under a managed work profile. Regulated or in-scope data — including cardholder data, personal data subject to statutory protection, and any information classified Confidential or above — may be processed only on corporate-owned, fully managed endpoints. Enrolment status is a condition of continued access, and devices that fall out of compliance are quarantined until remediated.
9. Removable Media and Data-Transfer Control
Use of removable media (USB drives, external disks, memory cards, and optical media) is restricted by default. Where a business need exists, media must be organisation-approved and, for regulated data, encrypted; auto-run is disabled and media is automatically scanned for malware on connection, consistent with PCI DSS v4.0.1 Requirement 5.3.3. Unauthorised or unrecognised devices are blocked through endpoint controls, and data written to removable media is logged. Personal removable media must not be connected to CDE systems.
10. Automatic Screen Lock and Session Protection
All endpoints must enforce an automatic screen lock after a defined period of inactivity — not exceeding fifteen (15) minutes for general endpoints and not exceeding fifteen (15) minutes for systems within the cardholder data environment — requiring re-authentication to resume. Users must also lock their session manually whenever a device is left unattended. Devices must not display credentials or sensitive data on screen where they can be observed by unauthorised persons, and unattended sessions must not be left authenticated to privileged systems.
11. Acceptable Use, User Responsibilities and Awareness
Users must not disable or tamper with anti-malware, encryption, or management agents; must not install unapproved software; and must promptly report a lost, stolen, or suspected-compromised device to the service desk. Software installation is restricted so that only approved applications may be introduced, supporting SOC 2 CC6.8. Personnel receive security-awareness training covering malware, phishing, and safe device handling; where the organisation is subject to PCI DSS, automated and process-based mechanisms to detect and protect against phishing are maintained in line with Requirement 5.4. Awareness training is completed at induction and refreshed at least annually.
12. Malware Response, Loss and Decommissioning
A suspected malware infection is treated as a security incident: the endpoint is isolated, investigated, cleaned or re-imaged, and only returned to service once verified clean, with the event handled under the organisation's incident-response process. Lost or stolen devices are remotely locked and wiped where possible. On return, reassignment, or disposal, endpoints and their storage media are securely sanitised so that no organisational information remains recoverable, and asset records are updated accordingly.
13. Monitoring, Compliance and Exceptions
Compliance with this policy is monitored through the central endpoint-management and EDR consoles, encryption-status reporting, and patch-compliance reporting, and is subject to periodic internal review and to audit by authorised internal and external assessors. Exceptions must be requested in writing, risk-assessed, time-bound, and approved by the Chief Information Security Officer ; approved exceptions are logged and reviewed at expiry. Non-compliance may result in loss of access and, where appropriate, disciplinary or contractual action.
14. Ownership and Review
This policy is owned by the Chief Information Security Officer , who is responsible for its maintenance, communication, and enforcement. It is reviewed at least annually, and additionally following any significant change to the threat landscape, technology estate, or applicable regulatory or contractual obligations. Approved revisions are versioned, dated, and communicated to all affected personnel.
Requirement Framework reference Where addressed User endpoint device protection ISO/IEC 27001:2022 A.8.1 Clauses 2, 6, 8, 10 Protection against malware ISO/IEC 27001:2022 A.8.7 Clauses 3, 4, 11, 12 Unauthorised / malicious software SOC 2 CC6.8 Clauses 3, 9, 11 Vulnerability & change detection SOC 2 CC7.1 Clauses 2, 7 Deploy & maintain anti-malware PCI DSS v4.0.1 Req 5.2 / 5.3 Clauses 3, 4 Automatic updates PCI DSS v4.0.1 Req 5.3.1 Clause 4 Periodic & real-time scanning PCI DSS v4.0.1 Req 5.3.2 Clause 4 Removable-media scanning PCI DSS v4.0.1 Req 5.3.3 Clauses 4, 9 Anti-malware audit logs PCI DSS v4.0.1 Req 5.3.4 Clause 4 Systems not at risk of malware PCI DSS v4.0.1 Req 5.2.3 Clause 5 Anti-phishing mechanisms PCI DSS v4.0.1 Req 5.4 Clause 11 Timely security patching PCI DSS v4.0.1 Req 6.3.3 Clause 7
Approved by
Head of IT Security
______________________
Title
Chief Information Security Officer
______________________