What Guide to Malware Incident Prevention and Handling for Desktops and Laptops requires
Malware, also known as malicious code, refers to a program that is covertly inserted into another program with the intent to destroy data, run destructive or intrusive programs, or otherwise compromise the confidentiality, integrity, or availability of the victim’s data, applications, or operating system. Malware is the most common external threat to most hosts, causing widespread damage and disruption and necessitating extensive recovery efforts within most organizations. This publication provides recommendations for improving an organization’s malware incident prevention measures. It also gives extensive recommendations for enhancing an organization’s existing incident response capability so that it is better prepared to handle malware incidents, particularly widespread ones. This revision of the publication updates material throughout to reflect the changes in threats and incidents. Unlike most malware threats several years ago, which tended to be fast-spreading and easy to notice, many of today’s malware threats are more stealthy, specifically designed to quietly, slowly spread to other hosts, gathering information over extended periods of time and eventually leading to exfiltration of sensitive data and other negative impacts. Organizations should develop and implement an approach to malware incident prevention based on current and future attack vectors, incorporating policy, awareness programs, vulnerability and threat mitigation, and defensive architecture.
Pillar: Cybersecurity · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-83r1.pdf
SHA-256 integrity: 6c17392bf4c8ecf95d6ee92cf75cf1c24c551297c763a41c4051492125ea7e77
Primary Citations — 9 traced to source
- Executive Summary: Organizations should have a robust incident response process capability that addresses malware incident handling.
- Section 3.1: Organizations should ensure that their policies address prevention of malware incidents.
+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access