Requirements / System and Information Integrity (SI)
SI.L2-3.14.4
Update Malicious Code Protection
Official Source Material
Update malicious code protection mechanisms when new releases are available.
Determine if:
- [a] malicious code protection mechanisms are updated when new releases are available.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
Automatic updates are the implementation. Anything manual is a liability.
Malware changes daily or faster, and [a] asks that protection mechanisms update when new releases are available. Turn on automatic definition and engine updates in the platform's policy and let the vendor's release cadence be your cadence.
The work is proving that automatic updates happen.
An auto-updating platform leaves no manual trail, so build one. Keep the policy export showing updates enabled and the vendor's documentation describing its release behavior. Add a console report showing agent and definition versions current across the fleet. Those three artifacts answer [a].
Watch for the agents that stop updating.
A machine with a stale definition version is this requirement failing quietly on one asset. Review the console's outdated-agent view on a schedule and chase the stragglers. The review record doubles as evidence the mechanism works.