Malware
Malware (malicious software) is any software designed to harm, exploit, or otherwise compromise computer systems. The term encompasses viruses, worms, ransomware, spyware, trojans, rootkits, and other malicious programs. Malware can steal data, encrypt files for ransom, spy on users, or give attackers remote control of infected systems.
Malware reaches your systems through email attachments, malicious websites, infected USB drives, compromised software updates, and exploitation of unpatched vulnerabilities. Defending against malware requires layered protections: email filtering, endpoint protection, application whitelisting, patch management, and user awareness training.
Why It Matters
Malware protection is explicitly required by CMMC. Implementing and maintaining effective anti-malware defenses — and keeping them updated — is a fundamental security control that assessors will verify on every endpoint in your CUI environment.