UCF STIG Viewer Logo

SharePoint-specific malware, (i.e., anti-virus), software must be integrated and configured.


Overview

Finding ID Version Rule ID IA Controls Severity
V-29339 SHPT-00-000683 SV-37995r1_rule ECCR-2 Medium
Description
Configuring anti-virus settings ensures documents will be scanned for viruses upon download from and upload to the SharePoint server. Anti-virus settings are not configured by default, therefore leaving the documents downloaded from or uploaded to SharePoint open to potential viruses.
STIG Date
SharePoint 2010 Security Technical Implementation Guide (STIG) 2011-12-20

Details

Check Text ( C-37299r1_chk )
1. Log on to Central Administrator.
2. Navigate to Operations > Security Configuration.
2. Select Anti-virus.
3. Mark as a finding if the following boxes are unselected:
- Scan documents on upload.
- Scan documents on download.
- Attempt to clean infected documents.
Fix Text (F-32536r1_fix)
Install and configure anti-virus package.
1. Install a SharePoint Server 2010-specific antivirus package.
2. Log in to Central Administration.
3. Navigate to Operations > Security Configuration.
4. Select Anti-virus.
5. Check the following boxes:
- Scan documents on upload.
- Scan documents on download.
- Attempt to clean infected documents.
6. Select "OK".