1Overview
SI.L2-3.14.4 keeps malicious code protection current. It requires that malicious code protection mechanisms be updated when new releases are available, so that the defenses providing malware protection stay effective against emerging threats. It is a five-point requirement that cannot be deferred on a plan of action.
Malware evolves constantly, and antimalware defenses depend on current signatures, engines, and definitions to recognize new threats. Protection that is not updated quickly falls behind, unable to detect the malware released after its last update. This control requires that malicious code protection mechanisms be updated when new releases are available, so the defenses stay current. Its five-point weight reflects that outdated malware protection provides a false sense of security while missing recent threats. The single assessment objective is that the mechanisms are updated when new releases are available.
Update malicious code protection mechanisms when new releases are available.
The requirement is to update malicious code protection mechanisms when new releases are available. In practice this means the antimalware signatures, engines, and definitions are kept current, typically through automatic updates, so protection recognizes the latest threats. The single assessment objective is that the mechanisms are updated when new releases become available.
2The Assessment Objective
NIST SP 800-171A frames 3.14.4 as a single objective: update mechanisms when new releases are available.
Malicious code protection mechanisms are updated when new releases are available. Antimalware stays current.
The single objective is timely updating. The common gap is antimalware present but not reliably updated, so its definitions lag behind current threats. The assessor looks for protection mechanisms kept current as new releases become available.
3Failure Patterns
The failures are about protection that falls behind.
Updates not automatic or not applied
Antimalware that relies on manual updates that lapse falls out of date. Automatic, applied updates keep protection current.
Some systems not updating
Where most systems update but some do not, those systems run stale protection. Updating has to reach all the protected systems.
Engine outdated, not just signatures
Updating signatures while leaving the protection engine outdated leaves detection gaps. Both the definitions and the mechanisms have to be updated.
4Ownership
This is an IT and security-owned control.
| Role | Responsibility for this control |
|---|---|
| IT and security | Keeps malicious code protection updated when new releases are available. Owns the update evidence. |
| System administrator | Configures and confirms automatic updates across systems. |
| Security or compliance lead | Confirms protection is current across all protected systems. |
5Tooling
The control is delivered by automatic antimalware updating.
| Objective | Tooling | What it provides |
|---|---|---|
| signatures | Automatic signature and definition updates | Current threat recognition. |
| engine | Engine and mechanism updates | Current protection mechanisms. |
The caveat is that updates have to actually apply across all protected systems, covering both definitions and mechanisms. Automatic updates that fail silently on some systems leave those running stale protection. The assessor examines whether the mechanisms are updated when new releases are available, so the updating has to be reliable and complete.
6Evidence
The satisfied version of 3.14.4 shows current malicious code protection.
| Evidence | What it demonstrates |
|---|---|
| Update configuration | The objective. Mechanisms set to update on new releases. |
| Update status records | The objective. Protection current across systems. |
The evidence should show malicious code protection mechanisms updated when new releases become available, across the protected systems. The update configuration together with update status records is the clearest demonstration, and because this control cannot sit on a plan of action, the current protection has to be real at the time of assessment.
Outdated antimalware protects against yesterday's threats
Malware evolves constantly, so protection that is not updated falls behind while looking like a defense, and this five-point control asks that the mechanisms be updated when new releases are available. Keeping malicious code protection current is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.4. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objective 3.14.4. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.4 among the five-point derived security requirements. ecfr.gov