STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288283

CAT II (Medium)

The application must be configured to perform real-time malicious code protection scans of files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy.

Rule ID

SV-288283r1252434_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-002624

Discussion

Malicious code protection mechanisms include, but are not limited to, antivirus and malware detection software. To minimize potential negative impact to the organization that can be caused by malicious code, it is imperative that malicious code is identified and eradicated. Malicious code includes viruses, worms, Trojan horses, and spyware. It is not enough to simply have the software installed; this software must periodically scan the system to search for malware on an organization-defined frequency. This requirement applies to applications providing malicious code protection.

Check Content

Review the anti-malware application documentation and deployed configuration to determine whether real-time malicious code protection scans are performed on files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy.

If the anti-malware application malicious code protection mechanisms are not configured to perform periodic real-time malicious code protection scans on files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy, this is a finding.

Fix Text

Configure the anti-malware application to perform real-time malicious code protection scans on files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy.