DKDavid Koran& Associates
Home The CMMC Guide Part III · System and Information Integrity SI.L2-3.14.5
The CMMC Guide · System and Information Integrity Family

SI.L2-3.14.5  Scan for Malicious Code

Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.

Family
System and Information IntegritySI, 7 requirements
Point Value
3Weighted above baseline
POA&M Eligible
NoAbove one point, cannot be deferred
Objectives
ThreePer NIST SP 800-171A

1Overview

SI.L2-3.14.5 requires active scanning for malicious code, both on a schedule and in real time. It requires that periodic scans of organizational systems be performed, along with real-time scans of files from external sources as they are downloaded, opened, or executed, so that malware is caught both proactively and at the moment of entry. It is a three-point requirement that cannot be deferred on a plan of action.

Malicious code protection works on two timescales: periodic scans that sweep systems for malware that may already be present, and real-time scanning that inspects files from external sources at the moment they arrive or run. This control requires both. Periodic scans, at a defined frequency, find dormant or missed malware; real-time scans of downloaded, opened, or executed files from external sources catch malware as it enters, before it can act. Together they cover both the resident threat and the incoming one. The three assessment objectives are defining the scan frequency, performing periodic scans, and performing real-time scans of external files.

The requirement · NIST SP 800-171 Rev 2, 3.14.5

Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.

The requirement combines periodic and real-time scanning. The assessment objectives make explicit that a scan frequency is defined, periodic scans are performed at that frequency, and real-time scans of files from external sources are performed as those files are downloaded, opened, or executed. The periodic scans sweep the systems; the real-time scans intercept incoming files at the moment of use. Both are required for complete coverage.

2The Assessment Objectives

NIST SP 800-171A decomposes 3.14.5 into three objectives: define the frequency, perform periodic scans, and perform real-time scans of external files.

[a]

The frequency for malicious code scans is defined. How often periodic scans run is set.

MeetsA frequency for periodic malicious code scans is defined.
FailsNo scan frequency is defined.
[b]

Malicious code scans are performed with the defined frequency. Periodic scans run on schedule.

MeetsPeriodic scans are performed at the defined frequency.
FailsPeriodic scans do not run on the defined schedule.
[c]

Real-time scans of files from external sources are performed as files are downloaded, opened, or executed. Incoming files are scanned at the moment of use.

MeetsExternal files are scanned in real time as they are downloaded, opened, or executed.
FailsExternal files are not scanned at the moment of entry.

The three objectives are the defined frequency, the periodic scans, and the real-time scans. The common gap is at objective [c], real-time scanning, where periodic scans run but incoming files are not inspected at the moment of use. The assessor looks for both periodic and real-time scanning.

3Failure Patterns

The failures are about incomplete scanning coverage.

Periodic only, no real-time

Scheduled scans that do not scan incoming files at the moment of use let malware act between scans. Real-time scanning catches it at entry.

Real-time only, no periodic

Real-time scanning without periodic sweeps misses malware that entered before protection was in place or slipped past. Periodic scans find resident threats.

No defined frequency

Without a defined scan frequency, periodic scanning has no cadence and lapses. Defining the frequency anchors the periodic scans.

The common root
This control fails when scanning covers one timescale but not the other. Periodic scans and real-time scans defend against different things, resident malware and incoming malware, so relying on one alone leaves the other threat open. Doing both is what gives malicious code scanning complete coverage.

4Ownership

This is an IT and security-owned control.

RoleResponsibility for this control
IT and securityConfigures periodic and real-time malicious code scanning. Owns the scan evidence.
Security or compliance leadDefines the scan frequency and confirms both scan types run.
Program leadReviews scan coverage and retains the records.
See also: This control uses the protection of SI.L2-3.14.2, kept current by SI.L2-3.14.4, and complements the vulnerability scanning of RA.L2-3.11.2.

5Tooling

The control is delivered by antimalware configured for periodic and real-time scanning.

ObjectivesToolingWhat it provides
[a], [b]Scheduled scan configurationPeriodic scans at the defined frequency.
[c]Real-time / on-access scanningExternal files scanned as downloaded, opened, or executed.

The caveat is that both scan types have to be active. Periodic scanning without real-time protection, or the reverse, leaves a coverage gap. The assessor examines the defined frequency, periodic scans, and real-time scans, so all three objectives have to hold.

6Evidence

The satisfied version of 3.14.5 shows both periodic and real-time scanning.

EvidenceWhat it demonstrates
Defined scan frequencyObjective [a]. The periodic scan cadence.
Periodic scan recordsObjective [b]. Scans performed on schedule.
Real-time scanning configurationObjective [c]. External files scanned at the moment of use.

The evidence should show a defined frequency, periodic scans performed at it, and real-time scanning of external files. The defined frequency together with the periodic scan records and real-time configuration is the clearest demonstration, and because this control cannot sit on a plan of action, both scan types have to be real at the time of assessment.

Resident malware and incoming malware are different threats

Periodic scans find what is already present while real-time scans catch what is arriving, so this three-point control asks for both. Configuring periodic and real-time scanning is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.

Start CMMC Readiness or call 802-335-2662

7Sources

  1. NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.5. csrc.nist.gov
  2. NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.14.5[a] through 3.14.5[c]. csrc.nist.gov
  3. 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.5 among the three-point derived security requirements. ecfr.gov
← Previous in System and Information Integrity
SI.L2-3.14.4 · Update Malicious Code Protection
Next in System and Information Integrity →
SI.L2-3.14.6 · Monitor for Attacks
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Entry SI.L2-3.14.5 · Edition 2026.1 · Last reviewed July 12, 2026