Rule ID
SV-288282r1252431_rule
Version
V1R0.1
CCIs
Malicious code protection mechanisms include, but are not limited to, antivirus and malware detection software. To minimize potential negative impact to the organization that can be caused by malicious code, it is imperative that malicious code is identified and eradicated. Malicious code includes viruses, worms, Trojan horses, and spyware. It is not enough to simply have the software installed; this software must periodically scan the system to search for malware on an organization-defined frequency. This requirement applies to applications providing malicious code protection.
Review the anti-malware application documentation and deployed configuration to determine whether periodic scans of the information system are performed every seven days. If the anti-malware application malicious code protection mechanisms are not configured to perform periodic scans of the information system every seven days, this is a finding.
Configure the anti-malware application to perform periodic scans of the information system every seven days.