All compliance pages

Anti-Virus Policy

Last reviewed: Updated 2025

Guidelines to prevent malware infections, system patching frequency, and antivirus sweeps on company terminals.

ANTIVIRUS & ENDPOINT PROTECTION

Policy Overview

FieldDetails
Reference No.DJTMPL/IT/POL/ANVR
Document NameAntivirus Policy
Policy OwnerChief Operation Officer
Policy Approving AuthorityBoard Of Directors
Version No.2.0
Document StatusDefinitive
Issue Date01-04-2026
Compliance StatusMandatory
Next Review Period01-04-2026
Security ClassificationInternal Use Only
DistributionDJTMPL

Document Revision History

VersionRelease DateChange Description
1.001-06-2024First version
2.001-04-2026Second version

Table Of Contents

S. NoParticulars
1Purpose
2Scope
3Policy Statement
4Technical Controls & Security Standards
5Roles & Responsibilities
6Monitoring & Compliance
7Incident Management
8Exceptions
9Non-Compliance
10Review & Version Control

1. Purpose

The purpose of this policy is to establish a comprehensive antivirus and endpoint protection framework to safeguard DJT Microfinance information systems, customer data, financial records, and digital assets against malware, ransomware, spyware, phishing, and other cyber threats.

2. Scope

This policy applies to all employees, contractors, consultants, and third-party users, covering all endpoints including desktops, laptops, tablets, smartphones, and servers — whether located at the Head Office, Branch Offices, or used in Field Operations. It further extends to all devices connected to the corporate LAN, WAN, VPN, cloud services, or the internet.

3. Policy Statement

All endpoints and servers must be protected using centrally managed, enterprise-grade Endpoint Protection Platform (EPP) and Endpoint Detection & Response (EDR) solutions. No device shall be permitted to access corporate resources without approved and active antivirus protection in place.

4. Technical Controls & Security Standards

4.1 Enterprise Antivirus Solution

The organisation shall deploy a centrally managed, RBI-compliant antivirus and EDR solution across all endpoints. Real-time protection must remain enabled at all times and must not be paused or disabled without formal written authorisation from the IT Department and the ISO. Tamper protection must be activated to prevent any unauthorised modification, disabling, or removal of the security software. A Central Security Console must monitor all enrolled endpoints continuously and generate alerts for any non-compliant, disconnected, or at-risk device.

4.2 Automated Updates

Virus definitions must update automatically at a minimum frequency of once per hour to ensure protection against the latest known threats. Security patches and engine updates must be deployed centrally through the management console, eliminating reliance on manual update processes. Any system that fails to receive timely updates — due to connectivity issues, device unavailability, or any other reason — must be automatically flagged in the Central Security Console and reported to the IT Department for follow-up investigation.

4.3 Endpoint Hardening

USB and device control must be enabled on all managed endpoints to prevent unauthorised peripheral devices from connecting and potentially introducing malware or exfiltrating sensitive data. All USB storage device connection attempts shall be logged, and connection of unapproved devices should trigger an immediate alert. Application control and whitelisting shall be implemented wherever technically feasible, restricting execution to a pre-approved list of software. The host-based firewall must remain enabled and correctly configured at all times. Full disk encryption is mandatory for all laptops and portable devices, ensuring that stored data remains inaccessible in the event of physical loss or theft.

4.4 Mobile Device Protection

All company-issued smartphones and tablets must be enrolled in an approved Mobile Device Management (MDM) platform before being permitted to access any corporate application, email, or data. The MDM solution enables the IT Department to enforce security policies, push configuration updates, manage application installations, and remotely wipe devices when necessary. Anti-malware protection must be installed and active on all Android-based devices. Remote wipe capability is mandatory; users who report a device as lost or stolen must notify the IT Department immediately so that a remote wipe can be initiated without delay.

4.5 Field Devices

Devices used by field employees — including loan officers, collection agents, and other customer-facing staff — must connect to corporate resources exclusively through a secure, encrypted VPN connection. Direct internet access to corporate systems without VPN is not permitted. Field devices must synchronise with the central security server at least once every 24 hours to receive updated policies, definition files, and to report their current security status. Installation of any unauthorised application on a field device is strictly prohibited; all software installation requests must go through the formal approval process managed by the IT Department.

4.6 Email & Web Protection

The email gateway must scan all inbound and outbound attachments for malicious content, with suspicious messages quarantined prior to delivery. Web filtering and anti-phishing protection must be enabled on all endpoints and at the network perimeter, preventing users from accessing known malicious websites, phishing pages, and untrusted download sources. Downloads of executable files, scripts, and other potentially dangerous file types from untrusted or uncategorised websites shall be blocked by default.

4.7 Removable Media Control

The use of USB storage devices and other removable media on organisational endpoints is restricted. Where business need justifies use of removable media, prior approval from the IT Department is required and the media must be encrypted and IT-issued. All removable media connected to an organisational endpoint must be automatically scanned upon connection. Any attempt to copy sensitive or classified data to a removable device must be logged, and where technically possible, blocked unless specifically authorised in writing. Audit logs of removable media activity must be retained and reviewed periodically as part of the compliance monitoring process.

4.8 Incident Detection & Response

The EDR component must be configured to detect advanced and subtle attack behaviours beyond simple signature matching, including ransomware encryption activity, privilege escalation attempts, lateral movement, credential dumping, and unusual process or network behaviour. Automated isolation of infected or compromised endpoints must be enabled so that, upon confirmed detection of a significant threat, the affected device is immediately disconnected from the network to prevent further spread. Security alerts generated by the EDR system must be reviewed by the IT Department within four working hours of generation. Unreviewed or unresolved alerts beyond this threshold must be escalated immediately to the Information Security Officer.

5. Roles & Responsibilities

5.1 Users

Every individual who uses a device covered by this policy bears personal responsibility for maintaining the security of that device and users must not, under any circumstances, disable, circumvent, pause, or tamper with the antivirus or endpoint protection software installed on their devices. Any suspicious activity — such as unexpected system slowdowns, unsolicited pop-up messages, software installations that the user did not initiate, or unusual network behaviour — must be reported immediately to the IT Department without delay. The installation of unauthorised software, including freeware, personal productivity tools, or any application not on the approved software list, is strictly prohibited. Users must follow all IT security instructions and directives issued by the IT Department and ISO, including instructions related to security updates, policy changes, and incident response procedures.

5.2 IT Department

The IT Department bears primary operational responsibility for the deployment, configuration, and ongoing maintenance of the endpoint protection platform across the entire organisation. This includes managing the Central Security Console, ensuring all in-scope endpoints are enrolled and reporting correctly, and responding promptly to all alerts and incidents in line with this policy. The security dashboard must be monitored on a daily basis, and a current inventory of all managed endpoints must be maintained at all times. When security alerts are triggered, the IT Department must investigate, determine severity, and execute appropriate response actions. All incidents, alerts, and response actions must be documented in a secure incident log retained for audit purposes. Regular compliance reports must be provided to management.

5.3 Information Security Officer

The Information Security Officer (ISO) holds overall accountability for the governance of this policy and the organisation's information security posture. The ISO must review this policy at least annually, or sooner upon material changes in the regulatory environment, a major security incident, or significant changes to the organisation's technology infrastructure. The ISO must ensure this policy and its controls remain fully aligned with the latest RBI Cyber Security Framework guidelines and any other applicable regulatory requirements. Periodic security audits must be commissioned to assess the effectiveness of endpoint protection controls and identify gaps or areas requiring improvement. Where major incidents carry regulatory reporting implications, the ISO is responsible for ensuring timely and accurate reports are submitted to management and relevant regulators within prescribed timeframes.

6. Monitoring & Compliance

A target of 100% endpoint coverage is required at all times, meaning every in-scope device must be enrolled in and actively protected by the organisation's endpoint protection solution. Monthly compliance reports must be generated from the Central Security Console and reviewed by the IT Department and ISO; these reports must document total endpoints managed, coverage percentages, devices quarantined or flagged, and the status of open alerts. Devices found to be non-compliant — whether due to outdated definitions, disabled protection, or failure to connect to the management server — shall be automatically quarantined until remediated. Internal audit shall review endpoint protection compliance at least annually, and all RBI and other regulatory audit requirements must be fully supported with relevant documentation, logs, and reports made available upon request.

7. Incident Management

Upon detection of a potentially infected or compromised endpoint — whether through the EDR(Endpoint Detection and Response System) a user report, or other means — the affected system must be immediately isolated from the corporate network to prevent spread of malware or unauthorised access. Isolation must not be delayed pending full confirmation where the risk of spread is material. Following isolation, a forensic investigation must be conducted by qualified IT security personnel, examining system logs, network traffic, file system changes, and other relevant evidence. Findings must be documented in a formal Incident Report including a Root Cause Analysis that identifies how the incident occurred, why existing controls failed, and what steps will prevent recurrence. Lessons learned must be formally incorporated into updates to security controls, user awareness training, or this policy. Major incidents must be escalated to the ISO and senior management within 24 hours of detection, with regulatory reporting fulfilled within timeframes specified by applicable rules.

8. Exceptions

Any exception to this policy must be formally requested in writing by the relevant business unit head or system owner, accompanied by a detailed description of the exception, the business justification, and a risk assessment documenting the security risks introduced and the compensating controls to be applied. All exception requests must be reviewed and approved by both Management and the Information Security Officer before taking effect; unauthorised exceptions are not permitted. Each approved exception must carry a clearly defined validity period and must be reviewed periodically. A register of all active exceptions must be maintained by the ISO.

9. Non-Compliance

Compliance with this policy is mandatory for all individuals and systems within its scope. Failure to comply may result in disciplinary action up to and including termination of employment, revocation of system and data access, and financial penalties where legally permissible. In cases of gross negligence, wilful circumvention of security controls, or malicious intent — such as deliberately introducing malware or exfiltrating data — the organisation reserves the right to pursue civil or criminal legal action against the responsible party.

10. Review & Version Control

This policy shall be reviewed at least annually by the ISO in consultation with the IT Department and senior management, assessing whether it remains fit for purpose and whether all requirements are being met in practice. An unscheduled review must be triggered by: issuance of new or updated RBI cybersecurity guidelines or other regulatory changes; occurrence of a major security incident that reveals gaps in current controls; significant technology upgrades that affect the scope or requirements of endpoint protection; or audit recommendations that necessitate policy changes. All revisions must be version-controlled, documenting the version number, date of approval, summary of changes, and approving authority. Superseded versions must be archived and retained for a minimum of five years to support audit and regulatory requirements. Upon approval of a new version, all employees and relevant stakeholders must be notified and the updated policy made accessible through standard distribution channels.