12. Identify, report, and correct system flaws promptly
Requirement: Find security flaws, report them through the appropriate process, and correct them in a timely manner.
Evidence examples: patch-management records, vulnerability findings, remediation tickets, update reports, and documented remediation timeframes.
13. Protect systems from malicious code
Requirement: Deploy malicious-code protection at appropriate locations within organizational systems.
Evidence examples: endpoint protection or anti-malware deployment reports, policy configuration, coverage reports, and alerting records.
14. Keep malicious-code protection current
Requirement: Update malicious-code protection mechanisms when new releases, signatures, or protection updates are available.
Evidence examples: update policies, endpoint-management reports, security-tool dashboards, and records showing current protection versions.
15. Perform periodic system scans and scan external files in real time
Requirement: Periodically scan the information system and scan files from external sources when they are downloaded, opened, or executed.
Evidence examples: scheduled scan configuration, scan reports, endpoint-protection settings, email or web security controls, and remediation records for detected threats.