UCF STIG Viewer Logo

The application must automatically update malicious code protection mechanisms, including signature definitions. Examples include anti-virus signatures and malware data files employed to identify and/or block malicious software from executing.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35683 SRG-APP-000272-AS-NA SV-46970r1_rule Medium
Description
Anti-virus and malicious software detection applications utilize signature definitions in order to identify viruses and other malicious software. These signature definitions need to be constantly updated in order to identify the new threats that are discovered every day. All anti-virus and malware software shall come with an update mechanism that automatically updates these signatures. The organization (including any contractor to the organization) is required to promptly install security-relevant malicious code protection software updates (e.g., anti-virus signature updates and hot fixes). Malicious code includes viruses, worms, Trojan horses, and Spyware. The requirement is NA. The AS does not provide malicious code protection.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-44025r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-40225r1_fix)
The requirement is NA. No fix is required.