NIST 800-171 · System and Information Integrity

Requirement 3.14.5

SPRS weight
SPRS weight: 3
POA&M eligibility
Not POA&M-eligible
Assessment objectives
3 assessment objectives

Official requirement text

Perform periodic scans of organizational systems and real-time scans of files from external sources as files are downloaded, opened, or executed.

Assessment objectives

Assessors don’t evaluate the requirement as one sentence; they walk these objectives one by one. Each must be met for the requirement to score.

  1. 3.14.5[a]the frequency for malicious code scans is defined.
  2. 3.14.5[b]malicious code scans are performed with the defined frequency.
  3. 3.14.5[c]real-time malicious code scans of files from external sources as files are downloaded, opened, or executed are performed.

Inside Valontir, this requirement carries a full plain-English guide: what it asks in normal words, what good looks like in a small shop, the evidence an assessor accepts, the common gaps that cost points, and a plain reading of every assessment objective shown above. See it in a demo.