NIST Issues Updated Guidance for Preventing and Handling Malware Incidents | Practical Law

NIST Issues Updated Guidance for Preventing and Handling Malware Incidents | Practical Law

The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) has published a Guide to Malware Incident Prevention and Handling for Desktops and Laptops.

NIST Issues Updated Guidance for Preventing and Handling Malware Incidents

Practical Law Legal Update 8-539-8265 (Approx. 3 pages)

NIST Issues Updated Guidance for Preventing and Handling Malware Incidents

by��Practical Law Intellectual Property & Technology
Published on 29 Aug 2013USA (National/Federal)
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) has published a Guide to Malware Incident Prevention and Handling for Desktops and Laptops.
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) published a Guide to Malware Incident Prevention and Handling for Desktops and Laptops (Guide) on July 27, 2013. The Guide provides:
  • Background information on major malware categories.
  • Recommendations for improving malware incident prevention measures.
  • Guidance for strengthening existing incident response capabilities to better handle malware incidents.
The Guide recommends that organizations:
  • Develop and implement an approach to preventing malware incidents.
  • Ensure that organizational policies address preventing malware incidents.
  • Include the prevention and handling of malware incidents in awareness programs.
  • Ensure vulnerability mitigation capabilities to help prevent malware incidents.
  • Perform threat mitigation to contain malware incidents.
  • Use defensive architecture methods to reduce the impact of malware incidents.
  • Develop a resilient incident response capability that includes:
    • preparation;
    • detection and analysis;
    • containment;
    • eradication;
    • recovery; and
    • post-incident activity.