This site has been deprecated in favor of https://attack.mitre.org and will remain in place until 11/1/22.
|NIST SP 800-53 Rev. 4||SI-3|
|IEC 62443-3-3:2013||SR 3.2|
|IEC 62443-4-2:2019||CR 3.2|
Use signatures or heuristics to detect malicious software.
Within industrial control environments, antivirus/antimalware installations should be limited to assets that are not involved in critical or real-time operations. To minimize the impact to system availability, all products should first be validated within a representative test environment before deployment to production systems.1
Techniques Addressed by Mitigation
|Spearphishing Attachment||Deploy anti-virus on all systems that support external email.|
|Transient Cyber Asset||Install anti-virus software on all workstation and transient assets that may have external access, such as to web, email, or remote file shares.|
|User Execution||Ensure anti-virus solution can detect malicious files that allow user execution (e.g., Microsoft Office Macros, program installers).|