McAfee VirusScan 8.8 Managed Client STIG
Open a previous version of this SCAP benchmark.
- RMF Control
- SI-3
- Severity
- H
- CCI
- CCI-001242
- Version
- DTAM001
- Vuln IDs
- V-6453
- Rule IDs
- SV-55134r1_rule
Fix: F-47991r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the General tab, locate the "Enable on-access scanning:" label. Select the "Enable on-access scanning at system startup" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM002
- Vuln IDs
- V-6467
- Rule IDs
- SV-55135r1_rule
Fix: F-47992r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the General tab, locate the "Scan:" label. Select the "Boot Sectors" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM003
- Vuln IDs
- V-6468
- Rule IDs
- SV-55139r1_rule
Fix: F-47997r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the General tab, locate the "Scan:" label. Select the "Floppy during shutdown" option. Select Save.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTAM004
- Vuln IDs
- V-6469
- Rule IDs
- SV-55141r1_rule
Fix: F-48000r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Messages tab, locate the "User message:" label. Select the "Show the messages dialog box when a threat is detected and display the specified text in the message" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM005
- Vuln IDs
- V-6470
- Rule IDs
- SV-55144r1_rule
Fix: F-48001r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Messages tab, locate the "Actions available to user:" label. Uncheck the "Remove messages from the list" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM009
- Vuln IDs
- V-6474
- Rule IDs
- SV-55145r1_rule
Fix: F-48004r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Reports tab, locate the "Log to file:" label. Select the "Enable activity logging and accept the default location for the log file or specify a new location" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM010
- Vuln IDs
- V-6475
- Rule IDs
- SV-55147r1_rule
Fix: F-48005r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Reports tab, locate the "Log file size:" label. Select the "Limit the size of log file" option. For the "Maximum log file size:", input a value of at least 10MB or more. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM012
- Vuln IDs
- V-6478
- Rule IDs
- SV-55148r1_rule
Fix: F-48006r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Reports tab, locate the "What to log in addition to scanning activity:" label. Select the "Session summary" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM013
- Vuln IDs
- V-6583
- Rule IDs
- SV-55149r1_rule
Fix: F-48007r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Reports tab, locate the "What to log in addition to scanning activity:" label. Select the "Failure to scan encrypted files" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001247
- Version
- DTAM016
- Vuln IDs
- V-6585
- Rule IDs
- SV-55151r4_rule
Fix: F-48009r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset for the task assignment, select Actions, select Agent, and Select Modify Tasks on a Single System. Select Actions, and select New Client Task Assignment. In the Task to Schedule: area, select McAfee Agent for the product. Select Product Update for the Task Type. Select Create New Task. Provide a descriptive name for the task. Locate the "Package Types:" label. Select the "Engine" and "DAT" options. Select Save. On the Schedule page, locate the "Schedule Status:" label, and select the "Enabled" option. Locate the "Schedule type:" label, and from the pull down menu, select at least "Daily". Select Next. On the Summary page, verify the settings and select Save. Update the client machine.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTAM021
- Vuln IDs
- V-6586
- Rule IDs
- SV-55153r2_rule
Fix: F-48011r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Scanning of email:" label. Select the "Enable on-delivery email scanning" option. Select Save.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTAM022
- Vuln IDs
- V-6587
- Rule IDs
- SV-55169r2_rule
Fix: F-48023r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Heuristics:" label. Select the "Find unknown program threats and trojans" option. Select Save.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTAM023
- Vuln IDs
- V-6588
- Rule IDs
- SV-55171r2_rule
Fix: F-48024r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Heuristics:" label. Select the "Find unknown macro threats" option. Select Save.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTAM027
- Vuln IDs
- V-6590
- Rule IDs
- SV-55174r2_rule
Fix: F-48028r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Locate in the Category column the On Delivery Email Scan Policies. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Compressed files:" label. Select the "Decode MIME encoded files" option. Select Save.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTAM028
- Vuln IDs
- V-6591
- Rule IDs
- SV-55177r2_rule
Fix: F-48030r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Email message body (for Microsoft Outlook only):" label. Select the "Scan email message body" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM029
- Vuln IDs
- V-6592
- Rule IDs
- SV-55178r2_rule
Fix: F-48032r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Actions tab, locate the "When a threat is found:" label. For the "Perform this action first:" pull down menu, select "Clean attachments". Select Save.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- DTAM035
- Vuln IDs
- V-6596
- Rule IDs
- SV-55187r2_rule
Fix: F-48041r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Delivery Email Scan Policies. Under the Reports tab, locate the "Log to file:" label. Select the "Enable activity logging and accept the default location for the log file or specify a new location" option. Select Save.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000140
- Version
- DTAM036
- Vuln IDs
- V-6597
- Rule IDs
- SV-55188r2_rule
Fix: F-48042r4_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Delivery Email Scan Policies. Under the Reports tab, locate the "Log file size:" label. Select the "Limit the size of log file" option. For the "Maximum log file size:", select a value of 10MB or more. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM045
- Vuln IDs
- V-6599
- Rule IDs
- SV-55191r4_rule
Fix: F-48045r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Scan Locations tab, locate the "Locations to scan:" label. In the drop-down menus, select "All fixed drives" or "All local drives" and "Running processes". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM046
- Vuln IDs
- V-6600
- Rule IDs
- SV-55192r3_rule
Fix: F-48046r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Scan Locations tab, locate the "Scan options:" label. Select the "Include subfolders" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM047
- Vuln IDs
- V-6601
- Rule IDs
- SV-55193r3_rule
Fix: F-48047r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Scan Locations tab, locate the "Scan options:" label. Select the "Scan boot sectors" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM048
- Vuln IDs
- V-6602
- Rule IDs
- SV-55194r3_rule
Fix: F-48048r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Scan Items tab, locate the "File types to scan:" label. Select the "All files" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM050
- Vuln IDs
- V-6604
- Rule IDs
- SV-55195r4_rule
Fix: F-48049r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Exclusions tab, locate the "What not to scan:" label. Ensure that no items are listed in this area.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM052
- Vuln IDs
- V-6611
- Rule IDs
- SV-55196r4_rule
Fix: F-48050r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Scan Items tab, locate the "Options:" label. Select the "Scan inside archives (e.g. .ZIP)" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM053
- Vuln IDs
- V-6612
- Rule IDs
- SV-55197r3_rule
Fix: F-48051r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Scan Items tab, locate the "Options:" label. Select the "Decode MIME encoded files" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM054
- Vuln IDs
- V-6614
- Rule IDs
- SV-55199r3_rule
Fix: F-48054r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Scan Items tab, locate the "Heuristics:" label. Select the "Find unknown program threats" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM055
- Vuln IDs
- V-6615
- Rule IDs
- SV-55201r3_rule
Fix: F-48055r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Scan Items tab, locate the "Heuristics:" label. Select the "Find unknown macro threats" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM056
- Vuln IDs
- V-6616
- Rule IDs
- SV-55203r3_rule
Fix: F-48057r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Actions tab, locate the "When a threat is found:" label. From the "Perform this action first:" pull down menu, select "Clean files". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM057
- Vuln IDs
- V-6617
- Rule IDs
- SV-55204r3_rule
Fix: F-48060r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Actions tab, locate the "When a threat is found:" label. From the "If the first action fails, then perform this action:" pull down menu, select "Delete files". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM059
- Vuln IDs
- V-6618
- Rule IDs
- SV-55209r3_rule
Fix: F-48064r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Reports tab, locate the "Log to file:" label. Select the "Enable activity logging and accept the default location for the log file or specify a new location" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM060
- Vuln IDs
- V-6620
- Rule IDs
- SV-55211r3_rule
Fix: F-48066r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Reports tab, locate the "Log file size:" label. Select the "Limit the size of log file" option. For the "Maximum log file size:", select a value of 10MB or more. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM063
- Vuln IDs
- V-6625
- Rule IDs
- SV-55212r3_rule
Fix: F-48067r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Reports tab, locate the "What to log in addition to scanning activity:" label. Select the "Failure to scan encrypted files" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM070
- Vuln IDs
- V-6627
- Rule IDs
- SV-55213r3_rule
Fix: F-48069r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". Select "Edit Assignment" in the Actions column. In the Task to Schedule: area, verify the Product is "VirusScan Enterprise 8.8.0" and the Task Type is "On Demand Scan". Select the schedule page. Locate the "Schedule type:" label. For the pull down menu, select "Weekly". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM090
- Vuln IDs
- V-14618
- Rule IDs
- SV-55214r1_rule
Fix: F-48070r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the ScriptScan tab, locate the "ScriptScan:" label. Select the "Enable scanning of scripts" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM091
- Vuln IDs
- V-14619
- Rule IDs
- SV-55217r1_rule
Fix: F-48072r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Blocking tab, locate the "Block the connection:" label. Select the "Block the connection when a threatened file is detected in a shared folder" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM092
- Vuln IDs
- V-14620
- Rule IDs
- SV-55219r1_rule
Fix: F-48073r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Blocking tab, locate the "Block the connection:" label. Enter a value in "Unblock connections after x minutes" where x is set to no less than 30 minutes. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM093
- Vuln IDs
- V-14621
- Rule IDs
- SV-55221r1_rule
Fix: F-48075r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Blocking tab, locate the "Block" label. Select the "Block the connection when a file with a potentially unwanted program is detected in a shared folder" option. Select OK to Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM100
- Vuln IDs
- V-14622
- Rule IDs
- SV-55222r1_rule
Fix: F-48078r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Processes tab, locate the "Process Settings:" label. Select the "Configure one scanning policy for all processes" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM101
- Vuln IDs
- V-14623
- Rule IDs
- SV-55224r1_rule
Fix: F-48079r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Scan files:" label. Select the "When writing to disk" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM102
- Vuln IDs
- V-14624
- Rule IDs
- SV-55225r1_rule
Fix: F-48081r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Scan files:" label. Select the "When reading from disk" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM103
- Vuln IDs
- V-14625
- Rule IDs
- SV-55228r1_rule
Fix: F-48083r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "File Types to Scan:" label. Select the "All Files" radio button option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM104
- Vuln IDs
- V-14626
- Rule IDs
- SV-55230r1_rule
Fix: F-48085r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Heuristics:" label. Select the "Find unknown unwanted programs and trojans" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM105
- Vuln IDs
- V-14627
- Rule IDs
- SV-55231r1_rule
Fix: F-48086r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Heuristics:" label. Select the "Find unknown macro threats" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM106
- Vuln IDs
- V-14628
- Rule IDs
- SV-55232r3_rule
Fix: F-48087r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Compressed files:" label. Select the "Scan inside archives (e.g. .ZIP)" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM110
- Vuln IDs
- V-14630
- Rule IDs
- SV-55233r1_rule
Fix: F-48088r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Actions tab, locate the "When a threat is found:" label. From the "Perform this action first:" pull down menu, select "Clean files automatically". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM111
- Vuln IDs
- V-14631
- Rule IDs
- SV-55234r1_rule
Fix: F-48089r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Actions tab, locate the "When a threat is found:" label. From the "If the first action fails, then perform this action:" pull down menu, select "Delete files automatically". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM039
- Vuln IDs
- V-14652
- Rule IDs
- SV-55189r2_rule
Fix: F-48043r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Delivery Email Scan Policies. Under the Actions tab, locate the "When an unwanted program is found:" label. From the "Perform this action first:" pull down menu, select "Clean attachments". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM058
- Vuln IDs
- V-14654
- Rule IDs
- SV-55207r3_rule
Fix: F-48061r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Scan Items tab, locate the "Options:" label. Select the "Detect unwanted programs" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM135
- Vuln IDs
- V-14662
- Rule IDs
- SV-55241r1_rule
Fix: F-48095r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select the policy associated with the Unwanted Programs Policies. Under the Scan Items tab, locate the "Select categories of unwanted programs to detect:" label. Select the "Spyware" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM136
- Vuln IDs
- V-14663
- Rule IDs
- SV-55242r1_rule
Fix: F-48096r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select the policy associated with the Unwanted Programs Policies. Under the Scan Items tab, locate the "Select categories of unwanted programs to detect:" label. Select the "Adware" option. Select Save.
- RMF Control
- SI-3
- Severity
- H
- CCI
- CCI-001240
- Version
- DTAG008
- Vuln IDs
- V-19910
- Rule IDs
- SV-55133r2_rule
Fix: F-47990r1_fix
Update client machines via ePO client task. If this fails to update the client, update antivirus signature files as your local process describes (e.g., auto update or runtime executable.)
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM137
- Vuln IDs
- V-35027
- Rule IDs
- SV-55243r1_rule
Fix: F-48097r3_fix
NOTE: For systems on the SIPRnet, this check is Not Applicable. From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the General tab, locate the "Artemis (Heuristic network check for suspicious files):" label. Select the "Medium" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM162
- Vuln IDs
- V-42493
- Rule IDs
- SV-55180r2_rule
Fix: F-48034r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Actions tab, locate the "When a threat is found:" label. For the "If the first action fails, then perform this action:" pull down menu, select "Delete attachments". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM163
- Vuln IDs
- V-42500
- Rule IDs
- SV-55190r2_rule
Fix: F-48044r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Actions tab, locate the "When an unwanted program is found:" label. From the "If the first action fails, then perform this action:" pull down menu, select "Delete attachments". Select Save.
- RMF Control
- SI-3
- Severity
- H
- CCI
- CCI-001242
- Version
- DTAM138
- Vuln IDs
- V-42516
- Rule IDs
- SV-55244r2_rule
Fix: F-48098r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select the policy associated with the Access Protection Policies. Under the Access Protection tab, locate the "Access protection settings:" label. Select the "Prevent McAfee services from being stopped" option. Select Save.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- DTAM139
- Vuln IDs
- V-42517
- Rule IDs
- SV-55245r2_rule
Fix: F-48099r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the Access Protection Policies. Under the Reports tab, locate the "Log to file:" label. Select the "Enable activity logging and accept the default location for the log file or specify a new location" option. Select Save.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000140
- Version
- DTAM140
- Vuln IDs
- V-42518
- Rule IDs
- SV-55246r2_rule
Fix: F-48100r1_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the Access Protection Policies. Under the Reports tab, locate the "Log file size:" label. Select the "Limit the size of log file" option. For the "Maximum log file size:", select a value of at least 10MB or more. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM152
- Vuln IDs
- V-42530
- Rule IDs
- SV-55258r2_rule
Fix: F-48112r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the ScriptScan tab, locate the "ScriptScan exclusions" label. Remove any exclusions listed in the Process field.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM153
- Vuln IDs
- V-42531
- Rule IDs
- SV-55259r4_rule
Fix: F-48113r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Exclusions tab, locate the "What not to scan:" label. Remove any exclusions listed.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- DTAM154
- Vuln IDs
- V-42532
- Rule IDs
- SV-55260r3_rule
Fix: F-48114r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Scan Locations tab, locate the "Locations to scan:" label. In the drop-down menus, select "Memory for rootkits". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM155
- Vuln IDs
- V-42533
- Rule IDs
- SV-55261r3_rule
Fix: F-48115r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Actions tab, locate the "When an unwanted program is found:" label. For the "Perform this action first:" pull down menu, select "Clean files". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM164
- Vuln IDs
- V-42534
- Rule IDs
- SV-55262r3_rule
Fix: F-48116r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Tasks on a Single System. From the list of available tasks in the Task Name column, with the assistance of the ePO SA, identify the weekly on demand client scan task. In the same row as the client scan task under review, under the Task Type column, ensure it is an "On Demand scan" and in the Status column, ensure that the status is "Enabled". In the Task Name column, select the weekly on demand task. Under the Actions tab, locate the "When an unwanted program is found:" label. From the "If the first action fails, then perform this action:" pull down menu, select "Delete files". Select Save.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTAM157
- Vuln IDs
- V-42536
- Rule IDs
- SV-55264r2_rule
Fix: F-48118r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Artemis (Heuristic network check for suspicious files):" label. Select the "Medium" option. Select Save.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- DTAM159
- Vuln IDs
- V-42538
- Rule IDs
- SV-55266r4_rule
Fix: F-48120r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Reports tab, locate the "What to log in addition to scanning activity:" label. Select the "Session summary" and "Failure to scan encrypted files" options. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM160
- Vuln IDs
- V-42539
- Rule IDs
- SV-55267r3_rule
Fix: F-48121r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the ScriptScan tab, locate the "ScriptScan exclusions" label. Remove any exclusions listed in the URL field.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM161
- Vuln IDs
- V-42540
- Rule IDs
- SV-55268r3_rule
Fix: F-48122r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select the policy associated with the Access Protection Policies. Under the Access Protection tab, locate the "Access protection settings:" label. Select the "Enable Access Protection" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM165
- Vuln IDs
- V-42541
- Rule IDs
- SV-55269r1_rule
Fix: F-48123r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Unwanted programs detection:" label. Place a check in the "Detect unwanted programs" checkbox. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM166
- Vuln IDs
- V-42542
- Rule IDs
- SV-55270r1_rule
Fix: F-48124r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Actions tab, locate the "When an unwanted program is found:" label. From the "Perform this action first:" pull down menu, select "Clean files automatically". Click OK to Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM167
- Vuln IDs
- V-42543
- Rule IDs
- SV-55271r2_rule
Fix: F-48125r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Actions tab, locate the "When an unwanted program is found:" label. From the "If the first action fails, then perform this action:" pull down menu, select "Delete files automatically". Click OK to Save.