Anti-Virus Policy¶
Anti-Virus Policy
Version history¶
| Version Number | Date | Description | Created By | Approved By |
|---|---|---|---|---|
| 0.1 | 23/Apr/2024 | Initial Copy | [Name] [Name] | |
| 0.2 | 18/Jun/2024 | Approved | [Name] [Name] | [Name] |
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
Purpose¶
The purpose of this policy is to protect tecciance information and underlying systems from potential damage from malicious codes. tecciance will ensure that precautions are implemented to detect and prevent the introduction of malicious code and unauthorized mobile code into the information processing facilities.
Scope¶
The scope of this policy shall be applicable to all the network devices, server systems, desktops, stand-alone systems, and mobile computing devices in tecciance. This procedure and guidelines are intended to implement a virus control system, which covers the mitigation of risk posed by malicious code in the enterprise network.
Roles and Responsibilities¶
The primary ownership of implementing this policy is with the IT Team. The IST shall implement this Procedure under the guidance of the Leadership Team and in coordination with Department Heads.
Policy¶
-
The IT Department shall ensure the implementation of necessary technical and operational procedures for centralized Antivirus definition updates.
-
The IT Department shall ensure that the Antivirus definition updates are up to date daily.
-
The IT Department shall be responsible to ensure that the Anti-virus software is installed and active on every machine.
-
Antivirus software shall be configured to install automatic updates of signature files promptly without requiring that end-user accepts/requests for updates.
-
Anti-Virus software shall be configured to prevent users from disabling it or modifying configuration settings.
-
The IT Team shall schedule the scanning of all machines in the network for virus detection periodically. The schedule shall be configured during less or off-peak traffic hours. (e.g., lunch hours)
-
All activities related to virus protection shall be logged, maintained, and reviewed periodically. IT team shall configure Anti-virus software in such a way that it scans every storage media for viruses before use. Any files or data obtained from outside through any media which will be required for business need shall be tested for viruses before being used.
-
Anti-virus software shall be deployed on an E-Mail server with virus detection and implement filtering controls. Necessary controls shall be deployed to control viruses being spread through E-mail attachments.
-
Appropriate recovery procedures shall be in place for recovering from malicious code attacks, including all necessary data and software backup and recovery arrangements. Appropriate technical measures shall be activated to ensure that the mobile codes are managed.
-
Use of mobile codes shall be allowed only after due approval from the Head – IT Department. Internet access shall be disabled from all key servers with the exception where it is required with authorization by Head – IT Department to ensure that malicious/mobile code does not affect the critical data on servers.
Procedure¶
General Guidelines¶
-
Enterprise-level Antivirus solution selected and authorized by tecciance should be implemented at tecciance network.
-
Anti-Virus clients should be installed on all servers, desktops, and laptops. All
-
incoming SMTP traffic from tecciance E-mail server should be scanned to remove the malicious code.
-
Anti-Virus agent should be configured to perform a real-time scan for all files being accessed.
-
Anti-Virus agents should be configured to quarantine virus-infected files if they cannot be cleaned.
-
Network scanning and cleaning activity for malicious code should be carried out every week.
-
The IT Department should ensure that new Anti-Virus signatures are applied as soon as they are released by the Anti-Virus solution vendor.
-
All systems in the tecciance network should be configured to get the signature updates from Anti-Virus Server.
-
The Anti-Virus Server should be configured to pick up the signature pattern from the vendor website.
Installation and configuration of anti-virus application¶
For devices running Windows, DOS, and Linux OS, Antivirus software shall be procured from the market and installed with the help of the IT team. For devices running Mac OS, in-built security features will be used.
Monitoring and managing virus-related activities¶
-
The IT Department should regularly monitor Virus Logs generated by anti-virus applications. In case a virus is found, the incident call shall be logged, and proper action should be taken against it.
-
The IT Department should review Anti-virus signature update logs generated by anti- virus applications on daily basis. In case any system is found not updated with the latest signature, the IT Department shall analyze the cause and update the system with the latest anti-virus signature.
Removal of Malicious Code¶
-
In case of a malicious code incident i.e., Virus, Trojan, etc. users should immediately close all programs on the system desktop.
-
The infected computer system shall NOT be shut down, as most viruses execute their “payload” during the boot process when you reboot it.
-
Infected systems should be immediately disconnected from the network. IT Department team members shall scan the entire machine using an Anti-virus solution with the latest update, which will either clean, quarantine, or delete the malicious code. Users shall report to IT.
-
Department about CD/floppy/Zip drives if used and have a suspicion that it contains malicious code.
General Guidelines for Users¶
-
Users shall not open any files or macros attached to an email from an unknown, suspicious, or untrustworthy source.
-
Users shall delete these attachments immediately, then empty the Recycle Bin.
-
Users shall delete Spam, chain, and other junk emails without forwarding them to any other user.
-
Users shall not download files from unknown or suspicious sources.
-
Users shall avoid direct disk sharing with read/write access unless there is absolutely a business requirement to do so.
-
Any removable media, CD / DVD / USB drives received from a known / unknown source shall be first scanned for viruses before using it. It is also applicable in the case of copying data from a standalone system that is connected to the Internet or to any network/desktop system.
-
User shall inform about the incidents related to virus infection to IT Support Team.
Guidelines to Protect against Mobile Code¶
Execution of mobile code will be restricted. If any Mobile code has to be executed, then approval should be taken from the IT Department. Such a system will be activated with specific technical control, which ensures to manage mobile code. Mobile code will be tested for Malicious Code prior to execution.
Reference¶
-
Anti-Virus Schedules
-
Quarantine Logs
-
Incident Register
Terms & Definitions¶
-
ISMS: Information Security Management System
-
IST: Information Security Team
-
Malicious Code: Malicious code is software designed to infiltrate or damage a computer system without the owner's informed consent. The expression is a general term used by computer professionals to mean a variety of forms of hostile, intrusive, or annoying software or program code. It includes computer viruses, Trojan horses, worms, spyware, dishonest adware, and other malware.
-
Mobile Code: Mobile code is software obtained from remote systems, transferred across a network, and then downloaded and executed on a local system without explicit installation or execution by the recipient. Examples of mobile code include scripts (JavaScript, VBScript), Java applets, ActiveX controls, Flash animations, Shockwave movies (and Extras), and macros embedded within Office documents.