Skip to content
arrow_back
search
Annex A 8.7 verified ISO/IEC 27001:2022

Protection against malware

Implement measures and train users to prevent and detect malware threats.

record_voice_over

Plain language

This control is all about stopping nasty software, like viruses or ransomware, from getting into your computer systems. If malware sneaks in, it could steal information, mess up your data, or even shut down important business operations, which could cost you time, money, and your hard-earned reputation.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Protection against malware shall be implemented and supported by appropriate user awareness.
verified ISO/IEC 27001:2022 Annex A 8.7
priority_high

Why it matters

Failure to prevent and detect malware (eg ransomware) can cause data theft, system outages and recovery costs, leading to regulatory and reputational harm.

settings

Operational notes

Regularly update malware definitions and conduct frequent user training to stay ahead of evolving threats and social engineering tactics.

Mapping detail

Mapping

Direction

Controls