Requirements / System and Information Integrity (SI)
SI.L2-3.14.2
Malicious Code Protection
Official Source Material
Provide protection from malicious code at designated locations within organizational systems.
Determine if:
- [a] designated locations for malicious code protection are identified; and
- [b] protection from malicious code at designated locations is provided.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Objective [a] is a list of locations, so write the list.
Designated locations are where malicious code can enter or take hold: workstations, servers, the email service, the web gateway or boundary firewall. Name them in your system security plan, the document that says how each requirement is met. The standard footprint is protection on every workstation and server operating system plus scanning where mail and web traffic enter.
Objective [b] is coverage at every location on the list.
Deploy the anti-malware or endpoint detection agent to each named endpoint and server, and turn on the mail and web scanning your platform provides. Reconcile the protection console against the asset inventory: a machine in the inventory with no agent is the finding waiting to be written.
Modern endpoint detection and response satisfies the requirement.
The objective asks for protection from malicious code, not for a signature-based product category. Endpoint detection and response, the tooling that watches program behavior instead of only matching known malware, meets it with real-time protection on. Reputation and behavior engines count. What matters is that every designated location has it and that it reports centrally.
Email and web are the delivery paths. Designate them.
Malicious code arrives through mail attachments, links, and downloads far more than through inbound network exploits. A designation list that stops at endpoints leaves the entry points unnamed under [a]. Include the mail filtering and web protection you already have.
What falls short
- Antivirus on workstations alone when servers and the email path are in scope. [a] asks where protection must be provided, and a list that omits the servers and entry points is incomplete.