1Overview
SI.L2-3.14.5 requires active scanning for malicious code, both on a schedule and in real time. It requires that periodic scans of organizational systems be performed, along with real-time scans of files from external sources as they are downloaded, opened, or executed, so that malware is caught both proactively and at the moment of entry. It is a three-point requirement that cannot be deferred on a plan of action.
Malicious code protection works on two timescales: periodic scans that sweep systems for malware that may already be present, and real-time scanning that inspects files from external sources at the moment they arrive or run. This control requires both. Periodic scans, at a defined frequency, find dormant or missed malware; real-time scans of downloaded, opened, or executed files from external sources catch malware as it enters, before it can act. Together they cover both the resident threat and the incoming one. The three assessment objectives are defining the scan frequency, performing periodic scans, and performing real-time scans of external files.
Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.
The requirement combines periodic and real-time scanning. The assessment objectives make explicit that a scan frequency is defined, periodic scans are performed at that frequency, and real-time scans of files from external sources are performed as those files are downloaded, opened, or executed. The periodic scans sweep the systems; the real-time scans intercept incoming files at the moment of use. Both are required for complete coverage.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.14.5 into three objectives: define the frequency, perform periodic scans, and perform real-time scans of external files.
The frequency for malicious code scans is defined. How often periodic scans run is set.
Malicious code scans are performed with the defined frequency. Periodic scans run on schedule.
Real-time scans of files from external sources are performed as files are downloaded, opened, or executed. Incoming files are scanned at the moment of use.
The three objectives are the defined frequency, the periodic scans, and the real-time scans. The common gap is at objective [c], real-time scanning, where periodic scans run but incoming files are not inspected at the moment of use. The assessor looks for both periodic and real-time scanning.
3Failure Patterns
The failures are about incomplete scanning coverage.
Periodic only, no real-time
Scheduled scans that do not scan incoming files at the moment of use let malware act between scans. Real-time scanning catches it at entry.
Real-time only, no periodic
Real-time scanning without periodic sweeps misses malware that entered before protection was in place or slipped past. Periodic scans find resident threats.
No defined frequency
Without a defined scan frequency, periodic scanning has no cadence and lapses. Defining the frequency anchors the periodic scans.
4Ownership
This is an IT and security-owned control.
| Role | Responsibility for this control |
|---|---|
| IT and security | Configures periodic and real-time malicious code scanning. Owns the scan evidence. |
| Security or compliance lead | Defines the scan frequency and confirms both scan types run. |
| Program lead | Reviews scan coverage and retains the records. |
5Tooling
The control is delivered by antimalware configured for periodic and real-time scanning.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [b] | Scheduled scan configuration | Periodic scans at the defined frequency. |
| [c] | Real-time / on-access scanning | External files scanned as downloaded, opened, or executed. |
The caveat is that both scan types have to be active. Periodic scanning without real-time protection, or the reverse, leaves a coverage gap. The assessor examines the defined frequency, periodic scans, and real-time scans, so all three objectives have to hold.
6Evidence
The satisfied version of 3.14.5 shows both periodic and real-time scanning.
| Evidence | What it demonstrates |
|---|---|
| Defined scan frequency | Objective [a]. The periodic scan cadence. |
| Periodic scan records | Objective [b]. Scans performed on schedule. |
| Real-time scanning configuration | Objective [c]. External files scanned at the moment of use. |
The evidence should show a defined frequency, periodic scans performed at it, and real-time scanning of external files. The defined frequency together with the periodic scan records and real-time configuration is the clearest demonstration, and because this control cannot sit on a plan of action, both scan types have to be real at the time of assessment.
Resident malware and incoming malware are different threats
Periodic scans find what is already present while real-time scans catch what is arriving, so this three-point control asks for both. Configuring periodic and real-time scanning is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.5. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.14.5[a] through 3.14.5[c]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.5 among the three-point derived security requirements. ecfr.gov