1Overview
SI.L2-3.14.2 requires protection against malicious code. It requires that protection from malicious code be provided at designated locations within organizational systems, so that malware is defended against at the points where it is likely to enter or spread. It is a five-point requirement that cannot be deferred on a plan of action.
Malicious code, viruses, worms, ransomware, and the rest, enters systems through email, downloads, removable media, and network paths. This control requires providing protection against it at designated locations: the organization identifies where malicious code protection is needed, the entry and transit points such as endpoints, servers, and email gateways, and then provides that protection there. Its five-point weight reflects that malware is among the most common and damaging threats. The two assessment objectives are identifying the designated locations and providing the protection.
Provide protection from malicious code at designated locations within organizational systems.
The requirement is to provide malicious code protection at designated locations. The assessment objectives split this into identifying those locations and providing the protection. Designated locations are the points where malicious code is likely to enter or move, workstations, servers, email systems, and network boundaries, and providing protection means deploying antimalware or equivalent defenses there. Placing protection at the right locations is what makes the defense effective.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.14.2 into two objectives: identify the designated locations and provide protection.
Designated locations for malicious code protection are identified. The points needing protection are known.
Protection from malicious code at designated locations is provided. Defenses are deployed at those points.
The two objectives are identification and provision. The common gap is at objective [b], where protection is present on some systems but not at all the designated locations, leaving entry points uncovered. The assessor looks for identified locations with protection provided at each.
3Failure Patterns
The failures are about gaps in malicious code coverage.
Protection on some systems only
Antimalware on workstations but not servers or email gateways leaves those locations exposed. Protection has to reach all the designated locations.
Locations not identified
Without identifying where malicious code protection is needed, coverage is haphazard. Identifying the designated locations directs the protection.
Protection present but not functioning
Antimalware installed but disabled or misconfigured provides no defense. The protection has to be actually operating at the designated locations.
4Ownership
This is an IT and security-owned control.
| Role | Responsibility for this control |
|---|---|
| IT and security | Identifies designated locations and provides malicious code protection. Owns the antimalware evidence. |
| System administrator | Deploys and maintains protection at the designated locations. |
| Security or compliance lead | Confirms protection covers all designated locations. |
5Tooling
The control is delivered by antimalware and equivalent protection at designated points.
| Objective | Tooling | What it provides |
|---|---|---|
| [a] | Location identification | The points needing malicious code protection. |
| [b] | Endpoint, server, and gateway antimalware | Protection provided at those points. |
The caveat is that protection has to be present and functioning at all the designated locations. Coverage of most systems with a gap at one entry point, or protection installed but disabled, leaves the control unmet. The assessor examines identification and provision, so both objectives have to hold.
6Evidence
The satisfied version of 3.14.2 shows protection at all designated locations.
| Evidence | What it demonstrates |
|---|---|
| Designated location list | Objective [a]. The points needing protection. |
| Antimalware deployment | Objective [b]. Protection provided at those points. |
The evidence should show designated locations identified and malicious code protection provided at each. The designated location list together with the antimalware deployment is the clearest demonstration, and because this control cannot sit on a plan of action, the protection has to be real at the time of assessment.
Malware enters wherever a path is left open
Protection that covers most locations but leaves one entry point exposed still admits malware, so this five-point control asks that protection be provided at all designated locations. Deploying that coverage is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.2. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.14.2[a] and 3.14.2[b]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.2 among the five-point basic security requirements. ecfr.gov