Docy Child

IT-4 Workstations – OS

Estimated reading: 2 minutes 659 views

What is this control about?

Both your software and hardware must be protected from potential threats. Antivirus solutions are typically the most used tools to protect workstations and software, including the OS (operating system).

Available tools in the marketplace

The following listing is “crowdsourced” from our customer base or from external research. TrustCloud does not personally recommend any of the tools below, because we haven’t personally used them.

Asset Monitoring / Endpoint Security Tools
Jamf (Mac-specific)
Mosyle (Mac-specific)
Kolide
Rippling
Duo
OSQuery (free, open source)

Available templates

TrustCloud has a curated list of templates internally or externally sourced to help you get started. Click on the link for a downloadable version:

  • N/A – no template for this control

Control implementation

Note: This control is 100% automated by TrustCloud. Connect your system to enjoy the benefit of automation

For a manual implementation: 

Install a centralized antivirus solution on all hardware (i.e workstations). In the event that some devices are not managed by the centralized solution, ensure that a BYOD policy exist (Bring Your Own Device) to shift the liability/responsibility for OS security to the end user and not the company.

What evidence do auditors look for?

Most auditors, at a minimum are looking for the below suggested action:

  • Provide screenshot of the antivirus policies and list of connected workstations
  • Provide screenshot of the antivirus policies and list of connected devices

Evidence example

From the suggested action above, an example is provided below.

  1. Provide a screenshot of the antivirus policies and list of connected workstations.

TrustCloud example showing the policies for one “device”

IT-4 Workstations - OS

2. Provide screenshot of the antivirus policies and list of connected devices

IT-4 Workstations - OS

Join the conversation

ON THIS PAGE
SUBSCRIBE
FlightSchool
SHARE THIS ARTICLE
Twitter Facebook LinkedIn

❤️  Joyfully crafted by a 100% distributed team.