Skip to content
arrow_back
ISM-1417policyASD Information Security Manual (ISM)

Ensure Antivirus Protection on Workstations and Servers

Install antivirus software on all computers and servers to detect and prevent malware and ransomware.

record_voice_over

Plain language

This control ensures that all computers and servers have antivirus software to protect against viruses and ransomware. Without it, malware can disrupt operations, steal data, or cause financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

An antivirus application is implemented on workstations and servers with: - signature-based detection functionality enabled and set to a high level - heuristic-based detection functionality enabled and set to a high level - reputation rating functionality enabled - ransomware protection functionality enabled - detection signatures configured to update at least daily - regular scanning configured for all fixed disks and removable media.
policyASD Information Security Manual (ISM)ISM-1417
priority_high

Why it matters

Without antivirus protection, computers risk malware infections that can cripple operations, leading to data theft and financial harm.

settings

Operational notes

Regularly check that antivirus protections are updated and scans are conducted on schedule to maintain security effectiveness.

build

Implementation tips

  • IT teams should install antivirus software on all company computers and servers. Find a reliable vendor and follow their guidelines to complete the installation on each device.
  • System owners should work with IT to configure antivirus settings. Ensure virus signature updates are automatic and happen every day to catch new threats.
  • Managers should verify that heuristic detection features are active. Heuristic detection helps catch unknown viruses by identifying suspicious behaviour.
  • IT staff should enable reputation rating and ransomware protection in the antivirus settings. This helps in blocking malicious software based on known bad behaviour and sources.
  • IT teams should schedule regular scans on all devices. Set up weekly scans to check all internal drives and any external media like USB sticks.
fact_check

Audit / evidence tips

  • Askthe antivirus software inventory listLook atwhether each workstation and server is includedGoodAll devices are listed with antivirus software version
  • GoodDaily updates with no interruptions longer than 24 hours
  • Askto see the configuration settings of antivirus programs. Check if heuristic and reputation-based detections are enabledGoodSettings are enabled and active
  • Look atregular scans and their frequencyGoodLogs show weekly scans with detailed results
  • Askincident reports related to antivirus detections. Examine the response actions taken and their timelinessGoodTimely responses with resolved cases
link

Cross-framework mappings

How ISM-1417 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
linkRelated(1)expand_less
Annex A 8.7ISM-1417 mandates detailed antivirus implementation requirements (signature and heuristic detection set high, reputation ratings, ransomw...

E8

ControlNotesDetails
handshakeSupports(1)expand_less
E8-RM-ML1.3ISM-1417 requires comprehensive antivirus on workstations and servers, including high-level detection settings, daily signature updates, ...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls