You know you bring up a good point, in that I don't think the relevant regulations like pic, hippa, etc ever really require a certain tool, just certain checks and verifications. It's generally industry "best practice" to install antimalware anywhere that can handle it, with even the formerly forbidden embedded devices getting it sometimes.
Honestly, hids like ossec seems more apropos for what businesses really want to know, eg, did files XYZ change and by what when?
Honestly, hids like ossec seems more apropos for what businesses really want to know, eg, did files XYZ change and by what when?