Skip to content
ControlVerdict
SI.L2-3.14.4addresses
SI.L2-3.14.4Update Malicious Code Protection [CUI Data]
Update malicious code protection mechanisms when new releases are available.
  • [a]

    malicious code protection mechanisms are updated when new releases are available.

View full control

Definitions update automatically within hours; stale-definition devices lose CUI access

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses the single Update Malicious Code Protection objective across every location designated for malicious code protection.

Automatic by default. Signature and intelligence updates are pulled automatically on the vendor's release cadence, multiple times daily, with cloud-delivered protection on so the endpoint also consults current cloud intelligence between definition drops. Platform and engine updates ride the same automatic channel; the organization does not pin an engine version, because pinning is how “updated when new releases are available” silently becomes “updated last quarter.”

Enforced freshness. Definition age is a compliance signal, not just a dashboard column. A device whose definitions are older than 3 days, or whose engine version falls behind the assigned baseline, is marked noncompliant and loses access to CUI applications through Conditional Access until it updates. This makes the update state self-correcting: the user's own workflow pushes them to reconnect and update rather than waiting on a help desk queue.

Update path availability. Endpoint egress rules permit the vendor's update endpoints explicitly in the enclave allow-list, so the deny-by-default egress policy cannot starve the very mechanism this practice depends on. Devices that cannot reach the vendor fall back to an internal distribution point.

Air-gapped hosts. The two lab hosts get a signed offline definition package on a controlled schedule — weekly, with the transfer logged in the same ticket queue. The procedure names the operator, records the package version applied, and includes verifying the signature before import. A missed week is a ticket, so a manual process still produces a record an assessor can sample.

Failure visibility. Update failures alert rather than silently retry forever. The queue receives an item for any device failing definition update three times consecutively, and for any managed device that has not reported a definition version in 48 hours.

Maintenance. Weekly report of definition age distribution and engine version spread across the fleet. Monthly confirmation that the offline package log has an entry for each week. Re-validate the update channel after major OS upgrades, which occasionally reset the update service state.

Accepted gap. One vendor-managed test appliance receives definition updates on the vendor's own schedule, which the organization cannot control or verify directly. It is on an isolated VLAN with no route to the enclave, and the vendor's update attestation is filed with the annual exception review.

What the evidence looks like

  • Endpoint protection policy showing automatic definition and engine updates enabled
  • Compliance policy definition keyed on definition age, with the Conditional Access dependency
  • Weekly definition-age and engine-version report for the fleet
  • Offline definition package log for the air-gapped hosts with operator and version per entry
  • Sample update-failure ticket and its resolution

Environment

Cloud-managed endpoint protection for the main fleet, plus two air-gapped lab hosts that must be updated by offline package.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.