CMMCpedia Download

Requirements / System and Information Integrity (SI)

SI.L2-3.14.4

Update Malicious Code Protection

Official Source Material

Update malicious code protection mechanisms when new releases are available.

Determine if:

  1. [a] malicious code protection mechanisms are updated when new releases are available.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Automatic updates are the implementation. Anything manual is a liability.

Malware changes daily or faster, and [a] asks that protection mechanisms update when new releases are available. Turn on automatic definition and engine updates in the platform's policy and let the vendor's release cadence be your cadence.

The work is proving that automatic updates happen.

An auto-updating platform leaves no manual trail, so build one. Keep the policy export showing updates enabled and the vendor's documentation describing its release behavior. Add a console report showing agent and definition versions current across the fleet. Those three artifacts answer [a].

Watch for the agents that stop updating.

A machine with a stale definition version is this requirement failing quietly on one asset. Review the console's outdated-agent view on a schedule and chase the stragglers. The review record doubles as evidence the mechanism works.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.