OPS-04—Protection Against Malware - Concept
>Control Description
Policies and instructions with specifications for protection against malware are documented, communicated, and provided in accordance with SP-01 with respect to the following aspects:
• Use of system-specific protection mechanisms;
• Operating protection programs on system components under the responsibility of the Cloud Service Provider that are used to provide the cloud service in the production environment; and
• Operation of protection programs for employees' terminal equipment.
Additional criteria: The Cloud Service Provider creates regular reports on the checks performed, which are reviewed and analysed by authorised bodies or committees. Policies and instructions describe the technical measures taken to securely configure and monitor the management console (both the customer's self-service and the service provider's cloud administration) to protect it from malware. Updates are applied at the highest frequency that the vendor(s) contractually offer(s).
Ask AI
Configure your API key to use AI features.