NIST 800-171 Controls · System and Information Integrity

SI.1.004Update Malicious Code Protection Mechanisms

CMMC Level 1SPRS if unmet: -3HIGH priority~2h to implement

Update malicious code protection mechanisms when new releases are available.

What SI.1.004 means in plain English

Your antivirus is only as good as its latest update. New viruses and malware are discovered every day, and your antivirus needs the latest definitions to catch them. Make sure virus definitions update automatically at least once per day. Also update the antivirus engine itself when new versions are released. If a computer has been offline for a while (like a laptop that was in a drawer for a month), update it before reconnecting it to the network.

The assessment question

Are antivirus and anti-malware definitions configured to update automatically at least daily, and are antivirus engine updates applied when new versions are released?

How to implement SI.1.004

  1. Verify Windows Defender automatic updates are enabled: Windows Security > Virus & Threat Protection > Protection updates > check that "Security intelligence" shows a recent update date (within 24 hours).
  2. Ensure Windows Update is set to install updates automatically, as Defender definition updates are delivered through Windows Update.
  3. For any offline or infrequently used devices, establish a procedure: before reconnecting to the network, connect to the internet, run Windows Update, and verify Defender definitions are current.
  4. If using a third-party antivirus, verify its automatic update settings are enabled and check the vendor's update frequency (should be at least daily).

Evidence your assessor will ask for

  • Windows Defender definition update timestamps showing daily updates across all systems
  • Windows Update configuration showing automatic updates are enabled
  • Antivirus engine version information showing the current version is installed
  • Procedure for updating offline devices before network reconnection

Does AI prompt monitoring help with this control? Honestly, no.

SI.1.004 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.

Full mapping: which 800-171 controls AI prompt monitoring evidences →

More System and Information Integrity controls

Score yourself against all 110 controls

The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.