last sync: 2024-Sep-19 17:51:32 UTC

Microsoft Managed Control 1676 - Malicious Code Protection | Regulatory Compliance - System and Information Integrity

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1676 - Malicious Code Protection
Id c10fb58b-56a8-489e-9ce3-7ffe24e78e4b
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this System and Information Integrity control
Additional metadata Name/Id: ACF1676 / Microsoft Managed Control 1676
Category: System and Information Integrity
Title: Malicious Code Protection - Detection/Eradication of Malicious Code
Ownership: Customer, Microsoft
Description: The organization: Employs malicious code protection mechanisms at information system entry and exit points to detect and eradicate malicious code;
Requirements: Servers : The use of anti-malware software is a principal mechanism for protection of Azure assets from malicious software. The software detects and prevents the introduction of computer viruses, malware, rootkits, worms, and other malicious software onto the service systems. Anti-malware software provides both preventive and detective control over malicious software. Approved tools such as System Center Endpoint Protection (SCEP), Microsoft Endpoint Protection (MEP), Microsoft Defender for Endpoint (MDE), and ClamAV are installed as part of the initial build on all servers, including all entry and exit points to the information system. Network Devices Network devices do not natively support anti-malware software, but are protected through a combination of the server-based anti-malware software and the secure coding practices required by the Security Development Lifecycle (SDL), configuration management and control, supply chain processes, and comprehensive logging and monitoring.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Microsoft.Resources/subscriptions
Microsoft.Resources/subscriptions/resourceGroups
Compliance Not a Compliance control
Initiatives usage none
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC