UCF STIG Viewer Logo

SharePoint-specific malware (i.e., anti-virus) software must be integrated and configured.


Overview

Finding ID Version Rule ID IA Controls Severity
V-29339 SHPT-00-000683 SV-37995r3_rule ECCR-2 High
Description
Configuring anti-virus settings ensures documents will be scanned for viruses upon download from and upload to the SharePoint server. Anti-virus settings are not configured by default, therefore leaving SharePoint document libraries open to potential viruses.
STIG Date
SharePoint 2010 Security Technical Implementation Guide (STIG) 2015-10-02

Details

Check Text ( C-37299r4_chk )
1. Verify a SharePoint specific antivirus solution is installed.
2. In SharePoint Central Administration, click Security.
3. On the Security page, in the General Security list, click Manage antivirus settings.
4. Mark as a finding if the following boxes are unchecked:
- Scan documents on upload.
- Scan documents on download.
- Attempt to clean infected documents.
Fix Text (F-32536r3_fix)
Install and configure anti-virus package.
1. Install a SharePoint specific antivirus solution.
2. In SharePoint Central Administration, click Security.
3. On the Security page, in the General Security list, click Manage antivirus settings.
4. Check the boxes for the following:
- Scan documents on upload.
- Scan documents on download.
- Attempt to clean infected documents.
5. Click OK.