UCF STIG Viewer Logo

The McAfee MOVE AV Agentless SVA policy must be configured with, and managed by, the HBSS ePO server.


Overview

Finding ID Version Rule ID IA Controls Severity
V-43957 AV-MOVE-SVA-001 SV-56787r2_rule Medium
Description
Organizations should use centrally managed antivirus software that is controlled and monitored regularly by antivirus administrators, who are also typically responsible for acquiring, testing, approving, and delivering antivirus signature and software updates throughout the organization. Users should not be able to disable or delete antivirus software from their hosts, nor should they be able to alter critical settings. Antivirus administrators should perform continuous monitoring to confirm that hosts are using current antivirus software and that the software is configured properly. Implementing all of these recommendations should strongly support an organization in having a strong and consistent antivirus deployment across the organization.
STIG Date
McAfee MOVE Agentless 3.0/3.6.1 Security Virtual Appliance STIG 2016-04-05

Details

Check Text ( C-49406r3_chk )
NOTE: MOVE Agentless 3.0/3.61 Security Virtual Appliance (SVA) comes pre-installed with McAfee Agent 4.8 and requires that the McAfee Agent 4.8 Extension already be installed on the ePO 4.6 Server. ePO 4.6 environments must upgrade to the McAfee Agent 4.8 Extension prior to deployment of the MOVE Agentless 3.0/3.61 SVA.

From the ePO server console System Tree, select "My Organization". Select the Systems tab. To show all systems in the System Tree, select "This Group and All Subgroups" from the "Preset:" drop-down list. From the list of systems, locate the asset representing the McAfee MOVE Security Virtual Appliance (SVA).

If the system designated as the McAfee MOVE Security Virtual Appliance (SVA) is not in the ePO server System Tree, this is a finding.

If the system designated as the McAfee MOVE Security Virtual Appliance (SVA) is in the ePO server System Tree, click on the system to open the System Information page.

On the System Information page, verify "MOVE AV [Agentless]" is listed as an Installed Product.

If the system does not show MOVE AV [Agentless] listed as an installed product, this is a finding.
Fix Text (F-49400r3_fix)
Obtain the McAfee Agent install files from the McAfee ePO server and install onto the McAfee SVA, following the same procedures as for any other Linux system being managed by the McAfee ePO server.

After installation, from the ePO server console System Tree, select "My Organization". Select the Systems tab. Find and double-click on the asset representing the McAfee MOVE Security Virtual Appliance (SVA) to open its properties.

Under "System Information" section, verify the "Last communication" date and time is within the time period designated by the "Agent-to-Server Communication Interval:" under the "McAfee Agent" section.
Under "System information" section, verify "MOVE AV [Agentless]" is listed as an installed product.