DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Information Integrity SI.L2-3.14.2
The CMMC Guide · System and Information Integrity Family

SI.L2-3.14.2  Malicious Code Protection

Provide protection from malicious code at designated locations within organizational systems.

Family
System and Information IntegritySI, 7 requirements
Point Value
5Highest weight in the methodology
POA&M Eligible
NoCannot remain open at assessment
Objectives
TwoPer NIST SP 800-171A

1Overview

SI.L2-3.14.2 requires protection against malicious code. It requires that protection from malicious code be provided at designated locations within organizational systems, so that malware is defended against at the points where it is likely to enter or spread. It is a five-point requirement that cannot be deferred on a plan of action.

Malicious code, viruses, worms, ransomware, and the rest, enters systems through email, downloads, removable media, and network paths. This control requires providing protection against it at designated locations: the organization identifies where malicious code protection is needed, the entry and transit points such as endpoints, servers, and email gateways, and then provides that protection there. Its five-point weight reflects that malware is among the most common and damaging threats. The two assessment objectives are identifying the designated locations and providing the protection.

The requirement · NIST SP 800-171 Rev 2, 3.14.2

Provide protection from malicious code at designated locations within organizational systems.

The requirement is to provide malicious code protection at designated locations. The assessment objectives split this into identifying those locations and providing the protection. Designated locations are the points where malicious code is likely to enter or move, workstations, servers, email systems, and network boundaries, and providing protection means deploying antimalware or equivalent defenses there. Placing protection at the right locations is what makes the defense effective.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.14.2 into two objectives: identify the designated locations and provide protection.

[a]

Designated locations for malicious code protection are identified. The points needing protection are known.

MeetsDesignated locations for malicious code protection are identified.
FailsNo designated locations are identified.
[b]

Protection from malicious code at designated locations is provided. Defenses are deployed at those points.

MeetsMalicious code protection is provided at the designated locations.
FailsDesignated locations lack malicious code protection.

The two objectives are identification and provision. The common gap is at objective [b], where protection is present on some systems but not at all the designated locations, leaving entry points uncovered. The assessor looks for identified locations with protection provided at each.

3Failure Patterns

The failures are about gaps in malicious code coverage.

Protection on some systems only

Antimalware on workstations but not servers or email gateways leaves those locations exposed. Protection has to reach all the designated locations.

Locations not identified

Without identifying where malicious code protection is needed, coverage is haphazard. Identifying the designated locations directs the protection.

Protection present but not functioning

Antimalware installed but disabled or misconfigured provides no defense. The protection has to be actually operating at the designated locations.

The common root
This control fails through partial coverage. Malicious code enters wherever a path is open, so protection that covers most locations but leaves one entry point exposed still admits malware through that gap. Identifying the designated locations and providing protection at each is what closes the paths.

4Ownership

This is an IT and security-owned control.

RoleResponsibility for this control
IT and securityIdentifies designated locations and provides malicious code protection. Owns the antimalware evidence.
System administratorDeploys and maintains protection at the designated locations.
Security or compliance leadConfirms protection covers all designated locations.
See also: This control works with the flaw remediation of SI.L2-3.14.1, its own updates at SI.L2-3.14.4, and the scanning of SI.L2-3.14.5.

5Tooling

The control is delivered by antimalware and equivalent protection at designated points.

ObjectiveToolingWhat it provides
[a]Location identificationThe points needing malicious code protection.
[b]Endpoint, server, and gateway antimalwareProtection provided at those points.

The caveat is that protection has to be present and functioning at all the designated locations. Coverage of most systems with a gap at one entry point, or protection installed but disabled, leaves the control unmet. The assessor examines identification and provision, so both objectives have to hold.

6Evidence

The satisfied version of 3.14.2 shows protection at all designated locations.

EvidenceWhat it demonstrates
Designated location listObjective [a]. The points needing protection.
Antimalware deploymentObjective [b]. Protection provided at those points.

The evidence should show designated locations identified and malicious code protection provided at each. The designated location list together with the antimalware deployment is the clearest demonstration, and because this control cannot sit on a plan of action, the protection has to be real at the time of assessment.

Malware enters wherever a path is left open

Protection that covers most locations but leaves one entry point exposed still admits malware, so this five-point control asks that protection be provided at all designated locations. Deploying that coverage is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.2. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.14.2[a] and 3.14.2[b]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.2 among the five-point basic security requirements. ecfr.gov
← Previous in System and Information Integrity
SI.L2-3.14.1 · Identify, Report, and Correct Flaws
Next in System and Information Integrity →
SI.L2-3.14.3 · Monitor Security Alerts and Advisories
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SI.L2-3.14.2 · Edition 2026.1 · Last reviewed July 12, 2026