Rule ID
SV-288283r1252434_rule
Version
V1R0.1
CCIs
Malicious code protection mechanisms include, but are not limited to, antivirus and malware detection software. To minimize potential negative impact to the organization that can be caused by malicious code, it is imperative that malicious code is identified and eradicated. Malicious code includes viruses, worms, Trojan horses, and spyware. It is not enough to simply have the software installed; this software must periodically scan the system to search for malware on an organization-defined frequency. This requirement applies to applications providing malicious code protection.
Review the anti-malware application documentation and deployed configuration to determine whether real-time malicious code protection scans are performed on files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy. If the anti-malware application malicious code protection mechanisms are not configured to perform periodic real-time malicious code protection scans on files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy, this is a finding.
Configure the anti-malware application to perform real-time malicious code protection scans on files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy.