McAfee VirusScan 8.8 Managed Client STIG
Open a previous version of this SCAP benchmark.
- RMF Control
- SI-3
- Severity
- H
- CCI
- CCI-001242
- Version
- DTAM001
- Vuln IDs
- V-6453
- Rule IDs
- SV-55134r1_rule
Fix: F-47991r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the General tab, locate the "Enable on-access scanning:" label. Select the "Enable on-access scanning at system startup" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM002
- Vuln IDs
- V-6467
- Rule IDs
- SV-55135r1_rule
Fix: F-47992r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the General tab, locate the "Scan:" label. Select the "Boot Sectors" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM003
- Vuln IDs
- V-6468
- Rule IDs
- SV-55139r1_rule
Fix: F-47997r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the General tab, locate the "Scan:" label. Select the "Floppy during shutdown" option. Select Save.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTAM004
- Vuln IDs
- V-6469
- Rule IDs
- SV-55141r1_rule
Fix: F-48000r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Messages tab, locate the "User message:" label. Select the "Show the messages dialog box when a threat is detected and display the specified text in the message" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM005
- Vuln IDs
- V-6470
- Rule IDs
- SV-55144r1_rule
Fix: F-48001r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Messages tab, locate the "Actions available to user:" label. Uncheck the "Remove messages from the list" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM009
- Vuln IDs
- V-6474
- Rule IDs
- SV-55145r1_rule
Fix: F-48004r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Reports tab, locate the "Log to file:" label. Select the "Enable activity logging and accept the default location for the log file or specify a new location" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM010
- Vuln IDs
- V-6475
- Rule IDs
- SV-55147r1_rule
Fix: F-48005r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Reports tab, locate the "Log file size:" label. Select the "Limit the size of log file" option. For the "Maximum log file size:", input a value of at least 10MB or more. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM012
- Vuln IDs
- V-6478
- Rule IDs
- SV-55148r1_rule
Fix: F-48006r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Reports tab, locate the "What to log in addition to scanning activity:" label. Select the "Session summary" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM013
- Vuln IDs
- V-6583
- Rule IDs
- SV-55149r1_rule
Fix: F-48007r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Reports tab, locate the "What to log in addition to scanning activity:" label. Select the "Failure to scan encrypted files" option. Select Save.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTAM021
- Vuln IDs
- V-6586
- Rule IDs
- SV-55153r2_rule
Fix: F-48011r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Scanning of email:" label. Select the "Enable on-delivery email scanning" option. Select Save.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTAM022
- Vuln IDs
- V-6587
- Rule IDs
- SV-55169r2_rule
Fix: F-48023r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Heuristics:" label. Select the "Find unknown program threats and trojans" option. Select Save.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- DTAM023
- Vuln IDs
- V-6588
- Rule IDs
- SV-55171r2_rule
Fix: F-48024r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Heuristics:" label. Select the "Find unknown macro threats" option. Select Save.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTAM027
- Vuln IDs
- V-6590
- Rule IDs
- SV-55174r2_rule
Fix: F-48028r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Locate in the Category column the On Delivery Email Scan Policies. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Compressed files:" label. Select the "Decode MIME encoded files" option. Select Save.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001170
- Version
- DTAM028
- Vuln IDs
- V-6591
- Rule IDs
- SV-55177r2_rule
Fix: F-48030r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Email message body (for Microsoft Outlook only):" label. Select the "Scan email message body" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM029
- Vuln IDs
- V-6592
- Rule IDs
- SV-55178r2_rule
Fix: F-48032r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Actions tab, locate the "When a threat is found:" label. For the "Perform this action first:" pull down menu, select "Clean attachments". Select Save.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- DTAM035
- Vuln IDs
- V-6596
- Rule IDs
- SV-55187r2_rule
Fix: F-48041r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Delivery Email Scan Policies. Under the Reports tab, locate the "Log to file:" label. Select the "Enable activity logging and accept the default location for the log file or specify a new location" option. Select Save.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000140
- Version
- DTAM036
- Vuln IDs
- V-6597
- Rule IDs
- SV-55188r2_rule
Fix: F-48042r4_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Delivery Email Scan Policies. Under the Reports tab, locate the "Log file size:" label. Select the "Limit the size of log file" option. For the "Maximum log file size:", select a value of 10MB or more. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM090
- Vuln IDs
- V-14618
- Rule IDs
- SV-55214r1_rule
Fix: F-48070r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the ScriptScan tab, locate the "ScriptScan:" label. Select the "Enable scanning of scripts" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM091
- Vuln IDs
- V-14619
- Rule IDs
- SV-55217r1_rule
Fix: F-48072r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Blocking tab, locate the "Block the connection:" label. Select the "Block the connection when a threatened file is detected in a shared folder" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM092
- Vuln IDs
- V-14620
- Rule IDs
- SV-55219r1_rule
Fix: F-48073r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Blocking tab, locate the "Block the connection:" label. Enter a value in "Unblock connections after x minutes" where x is set to no less than 30 minutes. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM093
- Vuln IDs
- V-14621
- Rule IDs
- SV-55221r1_rule
Fix: F-48075r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the Blocking tab, locate the "Block" label. Select the "Block the connection when a file with a potentially unwanted program is detected in a shared folder" option. Select OK to Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM100
- Vuln IDs
- V-14622
- Rule IDs
- SV-55222r1_rule
Fix: F-48078r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Processes tab, locate the "Process Settings:" label. Select the "Configure one scanning policy for all processes" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM101
- Vuln IDs
- V-14623
- Rule IDs
- SV-55224r1_rule
Fix: F-48079r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Scan files:" label. Select the "When writing to disk" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM102
- Vuln IDs
- V-14624
- Rule IDs
- SV-55225r1_rule
Fix: F-48081r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Scan files:" label. Select the "When reading from disk" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM103
- Vuln IDs
- V-14625
- Rule IDs
- SV-55228r1_rule
Fix: F-48083r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "File Types to Scan:" label. Select the "All Files" radio button option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM104
- Vuln IDs
- V-14626
- Rule IDs
- SV-55230r1_rule
Fix: F-48085r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Heuristics:" label. Select the "Find unknown unwanted programs and trojans" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM105
- Vuln IDs
- V-14627
- Rule IDs
- SV-55231r1_rule
Fix: F-48086r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Heuristics:" label. Select the "Find unknown macro threats" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM106
- Vuln IDs
- V-14628
- Rule IDs
- SV-55232r3_rule
Fix: F-48087r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Compressed files:" label. Select the "Scan inside archives (e.g. .ZIP)" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM110
- Vuln IDs
- V-14630
- Rule IDs
- SV-55233r1_rule
Fix: F-48088r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Actions tab, locate the "When a threat is found:" label. From the "Perform this action first:" pull down menu, select "Clean files automatically". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM111
- Vuln IDs
- V-14631
- Rule IDs
- SV-55234r1_rule
Fix: F-48089r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Actions tab, locate the "When a threat is found:" label. From the "If the first action fails, then perform this action:" pull down menu, select "Delete files automatically". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM039
- Vuln IDs
- V-14652
- Rule IDs
- SV-55189r2_rule
Fix: F-48043r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Delivery Email Scan Policies. Under the Actions tab, locate the "When an unwanted program is found:" label. From the "Perform this action first:" pull down menu, select "Clean attachments". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM135
- Vuln IDs
- V-14662
- Rule IDs
- SV-55241r1_rule
Fix: F-48095r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select the policy associated with the Unwanted Programs Policies. Under the Scan Items tab, locate the "Select categories of unwanted programs to detect:" label. Select the "Spyware" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM136
- Vuln IDs
- V-14663
- Rule IDs
- SV-55242r1_rule
Fix: F-48096r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select the policy associated with the Unwanted Programs Policies. Under the Scan Items tab, locate the "Select categories of unwanted programs to detect:" label. Select the "Adware" option. Select Save.
- RMF Control
- SI-3
- Severity
- H
- CCI
- CCI-001240
- Version
- DTAG008
- Vuln IDs
- V-19910
- Rule IDs
- SV-55133r2_rule
Fix: F-47990r1_fix
Update client machines via ePO client task. If this fails to update the client, update antivirus signature files as your local process describes (e.g., auto update or runtime executable.)
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM137
- Vuln IDs
- V-35027
- Rule IDs
- SV-55243r1_rule
Fix: F-48097r3_fix
NOTE: For systems on the SIPRnet, this check is Not Applicable. From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the General tab, locate the "Artemis (Heuristic network check for suspicious files):" label. Select the "Medium" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM162
- Vuln IDs
- V-42493
- Rule IDs
- SV-55180r2_rule
Fix: F-48034r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Actions tab, locate the "When a threat is found:" label. For the "If the first action fails, then perform this action:" pull down menu, select "Delete attachments". Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM163
- Vuln IDs
- V-42500
- Rule IDs
- SV-55190r2_rule
Fix: F-48044r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Actions tab, locate the "When an unwanted program is found:" label. From the "If the first action fails, then perform this action:" pull down menu, select "Delete attachments". Select Save.
- RMF Control
- SI-3
- Severity
- H
- CCI
- CCI-001242
- Version
- DTAM138
- Vuln IDs
- V-42516
- Rule IDs
- SV-55244r2_rule
Fix: F-48098r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select the policy associated with the Access Protection Policies. Under the Access Protection tab, locate the "Access protection settings:" label. Select the "Prevent McAfee services from being stopped" option. Select Save.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- DTAM139
- Vuln IDs
- V-42517
- Rule IDs
- SV-55245r2_rule
Fix: F-48099r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the Access Protection Policies. Under the Reports tab, locate the "Log to file:" label. Select the "Enable activity logging and accept the default location for the log file or specify a new location" option. Select Save.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000140
- Version
- DTAM140
- Vuln IDs
- V-42518
- Rule IDs
- SV-55246r2_rule
Fix: F-48100r1_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the Access Protection Policies. Under the Reports tab, locate the "Log file size:" label. Select the "Limit the size of log file" option. For the "Maximum log file size:", select a value of at least 10MB or more. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM152
- Vuln IDs
- V-42530
- Rule IDs
- SV-55258r2_rule
Fix: F-48112r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the ScriptScan tab, locate the "ScriptScan exclusions" label. Remove any exclusions listed in the Process field.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM153
- Vuln IDs
- V-42531
- Rule IDs
- SV-55259r5_rule
Fix: F-48113r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Exclusions tab, locate the "What not to scan:" label. Remove any exclusions listed.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- DTAM157
- Vuln IDs
- V-42536
- Rule IDs
- SV-55264r2_rule
Fix: F-48118r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Scan Items tab, locate the "Artemis (Heuristic network check for suspicious files):" label. Select the "Medium" option. Select Save.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- DTAM159
- Vuln IDs
- V-42538
- Rule IDs
- SV-55266r4_rule
Fix: F-48120r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On Delivery Email Scan Policies. Under the Reports tab, locate the "What to log in addition to scanning activity:" label. Select the "Session summary" and "Failure to scan encrypted files" options. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM160
- Vuln IDs
- V-42539
- Rule IDs
- SV-55267r3_rule
Fix: F-48121r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access General Policies. Under the ScriptScan tab, locate the "ScriptScan exclusions" label. Remove any exclusions listed in the URL field.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- DTAM161
- Vuln IDs
- V-42540
- Rule IDs
- SV-55268r3_rule
Fix: F-48122r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select the policy associated with the Access Protection Policies. Under the Access Protection tab, locate the "Access protection settings:" label. Select the "Enable Access Protection" option. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM165
- Vuln IDs
- V-42541
- Rule IDs
- SV-55269r1_rule
Fix: F-48123r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Scan Items tab, locate the "Unwanted programs detection:" label. Place a check in the "Detect unwanted programs" checkbox. Select Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM166
- Vuln IDs
- V-42542
- Rule IDs
- SV-55270r1_rule
Fix: F-48124r2_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Actions tab, locate the "When an unwanted program is found:" label. From the "Perform this action first:" pull down menu, select "Clean files automatically". Click OK to Save.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- DTAM167
- Vuln IDs
- V-42543
- Rule IDs
- SV-55271r2_rule
Fix: F-48125r3_fix
From the ePO server console System Tree, select the Systems tab, select the asset to be checked, select Actions, select Agent, and select Modify Policies on a Single System. From the product pull down list, select VirusScan Enterprise 8.8.0. Select from the Policy column the policy associated with the On-Access Default Processes Policies. Under the Actions tab, locate the "When an unwanted program is found:" label. From the "If the first action fails, then perform this action:" pull down menu, select "Delete files automatically". Click OK to Save.