UCF STIG Viewer Logo

The McAfee MOVE AV On Access Scan policy must be configured to scan files when writing to disk.


Overview

Finding ID Version Rule ID IA Controls Severity
V-78467 MV45-OAS-200004 SV-93173r1_rule Medium
Description
Anti-virus software is the most commonly used technical control for malware threat mitigation. Real-time scanning of files as they are written to disk is a crucial first line of defense from malware attacks.
STIG Date
McAfee MOVE AV Agentless 4.5 Security Technical Implementation Guide 2017-12-01

Details

Check Text ( C-78029r1_chk )
Access the McAfee ePO console.

Select Menu >> Policy >> Policy Catalog and then select "MOVE AntiVirus 4.5.0" from the Product list.

From the Category list, select "On Access Scan".

Select each configured On Access Scan policy.

Under "Scan", verify the "When writing to disk" check box is selected.

If the "When writing to disk" check box is not selected, this is a finding.
Fix Text (F-85201r1_fix)
Access the McAfee ePO console.

Select Menu >> Policy >> Policy Catalog and then select "MOVE AntiVirus 4.5.0" from the Product list.

From the Category list, select "On Access Scan".

Select each configured On Access Scan policy.

Under "Scan", select the "When writing to disk" check box.

Click "Save".