Requirements / System and Information Integrity (SI)
SI.L2-3.14.5
System & File Scanning
Official Source Material
Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.
Determine if:
- [a] the frequency for malicious code scans is defined;
- [b] malicious code scans are performed with the defined frequency; and
- [c] real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed.
Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024
Practitioner Guidance
How to meet it
The requirement contains two duties, and real-time scanning alone fails one of them.
Periodic scans of the system under [a] and [b] and real-time scans of external files under [c] are independent clauses. Define a scan frequency, run the scans on it, and keep real-time protection on. Continuous protection with no defined periodic scan leaves [a] with no number and [b] with no proof.
You choose the scan type and the frequency. Then match the configuration.
The requirement never says full scans. A weekly quick scan is a defensible definition when real-time protection covers file activity. What fails is a configuration that does not match your written frequency. Say what you do, do what you say, and export the schedule as evidence.
Real-time means on download, open, or execute, and a USB stick is an external source.
Endpoint real-time protection covers files as they arrive and run, and the email service's attachment scanning covers the main delivery path before files reach the endpoint [c]. Confirm scanning fires on removable media, because files copied from a USB drive are files from an external source.
Endpoint products without a scheduled scan feature need a documented equivalence.
Some platforms are designed for continuous scanning and offer no periodic scan to schedule. Collect the vendor's documentation of how every file is examined regardless, and define your frequency in those terms. Put the rationale in your system security plan, the document that says how each requirement is met, before an assessor asks.
What falls short
- Real-time protection with no defined scan frequency. [a] asks for a frequency and [b] for scans performed on it, and continuous protection does not answer either on its own.
Edge cases
- Repositories too large to scan wholesale get a defined approach, not silence: scan the ingestion points and designated locations, use quick scans, and document why that coverage is complete.
- Phones and tablets under mobile device management are handled through enrollment, app protection, patching, and jailbreak detection, which flags a phone stripped of its built-in protections. Document that mobile stack instead of forcing a traditional antivirus product onto iOS.