The place had so many dysfunctions I'd not know how to start. I work for a much more professional outfit now with true appreciation for security and competence.
edit: there's a real gap in this non-glamorous compliance domain. if you address it and need to execute SCAP (OVAL, XCCDF) content, look to a very competent scanner vendor, jOVAL. The real challenges are in organizing and presenting consistent info across many compliance standards, OSs, cloud vendors, etc. ... and to scan entities that aren't OSs per se, and to analyze cross-domain conditions.
Relevant: "How do I give our security auditor the information he wants? (2011)" https://news.ycombinator.com/item?id=12434215
Further, if you can demonstrate in auditable fashion that there are no browsers or other network connections or other typical vectors for infection, that can be a compensating control.
[Edit]
Or if you can demonstrate that your email system will drop all attachments and links, that would be another (annoying) way.
So to put it another way: can you set and enforce a policy as to how files get to your aws instance, set and enforce a policy as to how (that is with what programs) those files are accessed. And that there is a way to audit that such a policy is in place and enforced.
As an example Azure its own self is ISO 27001 (and a metric ton of other certs) and they don't run AV on their stuff. But you can be sure that they can tell you everything about each of the components that make up Azure itself up to the hypervisor level. I would presume that the same thing is true for AWS.
So now you put your stuff on top of this base service. If you can assure the auditors that you have somehow controlled that particular risk, then you won't need AV.
Also, of the 114 controls in ISO 27001, not all of the controls are relevant for the scope that you choose. You could say that "since we have total control of the character and nature files that land on each of our VMs, we don't need to have that control". Often you may need only 50 of the controls.
The thing about ISO 27001 is about understanding the risk that your systems in scope are subject to (e.g., loss of PCI-protected data, fire, downtime), building policies and procedures addressing those risks, and repeatedly auditing that those policies and procedures are in place and adjusting them when they are not.
Pro-Tip: don't take the approach of telling the auditors that AV is a fundamental risk. That conversation is not likely to be productive. Just demonstrate your control over the environment.
ISO 27001 is not that far removed from common-sense security.
You do a risk assessment, and if you can reasonably argue that you can mitigate the risk without antivirus, you're fine.
It's different with PCI-DSS and other standards: those actually have stricter requirements (you don't get to do a risk assessment yourself).
Ping me if you have more questions! Glad to elaborate.
Ran into this sort of thing at a .gov during audits for systems accreditation in 200x. I made the mistake of using 'mitigation' in my documentation and opened up a can of worms with the contracted auditing firm. They should have provided a glossary of weasel words.
Took twice as long to get the system accredited because of a common sense initial approach.
"Thinking that a huge program, written in C, with a code base from the 90ies, running as root or, even worst, in kernel space and parsing untrusted inputs by definition can improve security is kind of crazy."
From what I've seen in the Linux world, Anti-virus software tends to be pretty bad.
I've already posted something about the TrendMicro one here: https://news.ycombinator.com/item?id=10883777
The Kaspersky one, last time I checked, looked a little better (proper packaging and integration) but it seemed somewhat neglected (no 64bits version, no support for newer debian/ubuntu/RedHat releases).
The only commercial one which seems to be properly maintained on Linux was Sophos, it even has an open sourced working kernel module for realtime scanning (and it also supports the dnotily API). But it had some scary security flaws in the past: https://community.sophos.com/kb/en-us/118424
If you really have to use an AV, the least worst option is ClamAV, at least it's Open Sourced and packaged in most distributions. With the dnotify kernel API it can do realtime analysis.
Depending on what you mean, perhaps you want to get in touch if you'd like better technical due diligence :)
If having an antivirus can create possibly more security holes than it closes - then from an insurance perspective they would not want you to have it.
i.e. if they have to pay based upon an attack - they want to ensure the lowest risk.
With that said I prefer to view security as, "You likely will be the victim of a planned attack, so plan from there", but still. Odds are not favourable.
All auditors looking at you for this certification will ask this question.
But as I note in other threads, you have a good chance of demonstrating some compensating controls.