Ensure Antivirus Protection on Workstations and Servers
Install antivirus software on all computers and servers to detect and prevent malware and ransomware.
Plain language
This control ensures that all computers and servers have antivirus software to protect against viruses and ransomware. Without it, malware can disrupt operations, steal data, or cause financial loss.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
An antivirus application is implemented on workstations and servers with: - signature-based detection functionality enabled and set to a high level - heuristic-based detection functionality enabled and set to a high level - reputation rating functionality enabled - ransomware protection functionality enabled - detection signatures configured to update at least daily - regular scanning configured for all fixed disks and removable media.
Why it matters
Without antivirus protection, computers risk malware infections that can cripple operations, leading to data theft and financial harm.
Operational notes
Regularly check that antivirus protections are updated and scans are conducted on schedule to maintain security effectiveness.
Implementation tips
- IT teams should install antivirus software on all company computers and servers. Find a reliable vendor and follow their guidelines to complete the installation on each device.
- System owners should work with IT to configure antivirus settings. Ensure virus signature updates are automatic and happen every day to catch new threats.
- Managers should verify that heuristic detection features are active. Heuristic detection helps catch unknown viruses by identifying suspicious behaviour.
- IT staff should enable reputation rating and ransomware protection in the antivirus settings. This helps in blocking malicious software based on known bad behaviour and sources.
- IT teams should schedule regular scans on all devices. Set up weekly scans to check all internal drives and any external media like USB sticks.
Audit / evidence tips
- Askthe antivirus software inventory listLook atwhether each workstation and server is includedGoodAll devices are listed with antivirus software version
- GoodDaily updates with no interruptions longer than 24 hours
- Askto see the configuration settings of antivirus programs. Check if heuristic and reputation-based detections are enabledGoodSettings are enabled and active
- Look atregular scans and their frequencyGoodLogs show weekly scans with detailed results
- Askincident reports related to antivirus detections. Examine the response actions taken and their timelinessGoodTimely responses with resolved cases
Cross-framework mappings
How ISM-1417 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
linkRelated(1)expand_less | ||
| Annex A 8.7 | ISM-1417 mandates detailed antivirus implementation requirements (signature and heuristic detection set high, reputation ratings, ransomw... | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| E8-RM-ML1.3 | ISM-1417 requires comprehensive antivirus on workstations and servers, including high-level detection settings, daily signature updates, ... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.