malicious code protection mechanism
A category of security control — specifically, any technical tool, method, or combination thereof deployed at system entry/exit points and endpoints to detect, block, quarantine, or eradicate software or code intended to compromise a system. Such mechanisms include both signature- and nonsignature-based technologies; nonsignature-based detection includes artificial intelligence and heuristic techniques used to analyze the characteristics or behavior of malicious code, including cases where signatures do not yet exist or are ineffective. In compliance frameworks (NIST SP 800-53 SI-3, NIST SP 800-171, CMMC), the term functions as a collective label for the full suite of countermeasures an organization must deploy, configure, and keep current — employed at information system entry and exit points to detect and eradicate malicious code, updated whenever new releases are available, and configured to perform both periodic and real-time scans.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 6 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A category of security control — specifically, any technical tool, method, or combination thereof deployed at system entry/exit points and endpoints to detect, block, quarantine, or eradicate software or code intended to compromise a system. Such mechanisms include both signature- and nonsignature-based technologies; nonsignature-based detection includes artificial intelligence and heuristic techniques used to analyze the characteristics or behavior of malicious code, including cases where signatures do not yet exist or are ineffective. In compliance frameworks (NIST SP 800-53 SI-3, NIST SP 800-171, CMMC), the term functions as a collective label for the full suite of countermeasures an organization must deploy, configure, and keep current — employed at information system entry and exit points to detect and eradicate malicious code, updated whenever new releases are available, and configured to perform both periodic and real-time scans.DR-088 backfill from the noun definition column