NIST 800-171 Controls · System and Information Integrity
SI.1.004 — Update Malicious Code Protection Mechanisms
Update malicious code protection mechanisms when new releases are available.
What SI.1.004 means in plain English
Your antivirus is only as good as its latest update. New viruses and malware are discovered every day, and your antivirus needs the latest definitions to catch them. Make sure virus definitions update automatically at least once per day. Also update the antivirus engine itself when new versions are released. If a computer has been offline for a while (like a laptop that was in a drawer for a month), update it before reconnecting it to the network.
The assessment question
“Are antivirus and anti-malware definitions configured to update automatically at least daily, and are antivirus engine updates applied when new versions are released?”
How to implement SI.1.004
- Verify Windows Defender automatic updates are enabled: Windows Security > Virus & Threat Protection > Protection updates > check that "Security intelligence" shows a recent update date (within 24 hours).
- Ensure Windows Update is set to install updates automatically, as Defender definition updates are delivered through Windows Update.
- For any offline or infrequently used devices, establish a procedure: before reconnecting to the network, connect to the internet, run Windows Update, and verify Defender definitions are current.
- If using a third-party antivirus, verify its automatic update settings are enabled and check the vendor's update frequency (should be at least daily).
Evidence your assessor will ask for
- Windows Defender definition update timestamps showing daily updates across all systems
- Windows Update configuration showing automatic updates are enabled
- Antivirus engine version information showing the current version is installed
- Procedure for updating offline devices before network reconnection
Does AI prompt monitoring help with this control? Honestly, no.
SI.1.004 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More System and Information Integrity controls
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.