Rule ID
SV-288284r1252437_rule
Version
V1R0.1
CCIs
Malicious code protection mechanisms include, but are not limited to, antivirus and malware detection software. To minimize potential negative impact to the organization that can be caused by malicious code, it is imperative that malicious code is identified and eradicated. Applications providing this capability must be able to perform actions in response to detected malware. Responses include blocking, quarantining, deleting, and alerting. Other technology- or organization-specific responses may also be employed to satisfy this requirement. Malicious code includes viruses, worms, Trojan horses, and spyware. This requirement applies to applications providing malicious code protection.
Review the anti-malware application documentation and deployed configuration to determine whether malicious code is blocked and quarantined upon detection. If the anti-malware application malicious code protection mechanisms are not configured to block and quarantine malicious code upon detection, this is a finding.
Configure the anti-malware application to block and quarantine malicious code upon detection.