UCF STIG Viewer Logo

The IDPS must only update malicious code protection mechanisms when directed by a privileged user.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000253-IDPS-000224 SRG-NET-000253-IDPS-000224 SRG-NET-000253-IDPS-000224_rule Medium
Description
Malicious code includes viruses, worms, Trojan horses, and spyware. It is critical the protection mechanisms used to detect and contain this code are not tampered with by unauthorized users and are only updated when directed by a privileged user.
STIG Date
IDPS Security Requirements Guide (SRG) 2012-03-08

Details

Check Text ( C-43388_chk )
Verify only authenticated and authorized system administrators have access to the update functionality for malicious code protection mechanisms and signatures.

If malicious code protection installed on the IDPS components is not configured to allow only authorized system administrators to update the software, this is a finding.
Fix Text (F-43388_fix)
Remove permissions from system administrators who are not authorized for access to malicious code protection mechanisms and signature file configuration functionality.