UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

An approved, up-to-date, DOD antivirus program must be installed and used.


Overview

Finding ID Version Rule ID IA Controls Severity
V-1074 5.007 SV-29468r2_rule ECVP-1 High
Description
Antivirus programs are a primary line of defense against the introduction of viruses and malicious code that can destroy data and even render a computer inoperable. Utilizing an antivirus program provides the ability to detect malicious code before extensive damage occurs. Updated virus scan data files help to protect a system, since new malware are identified by the software vendors on a continual basis.
STIG Date
Windows 2003 Domain Controller Security Technical Implementation Guide 2015-03-09

Details

Check Text ( C-51967r1_chk )
V-19910 has been added as part of the McAfee and Symantec antivirus STIGs for signature files. If the system uses one of these programs, address them with that requirement and mark this one as N/A.

If none of the following products are installed and supported at an appropriate maintenance level, this is a finding:

Symantec Antivirus at the following level is not installed:
Corporate Edition Version 9.0.6 or higher
Corporate Edition Version 10.x or higher
Endpoint Protection Version 11.0 or higher

McAfee’s Antivirus Version 8.0 or higher is not installed.

And
The antivirus signature file is out of date.
If the antivirus program signature file has not been dated within the past 7 days, this is a finding.

Note: The version numbers and the date of the signature file can generally be checked by starting the antivirus program from the toolbar icon or from the Start menu. The information may appear in the antivirus window or be available in the Help > About window. The location varies from product to product.

Note: E-mail versions of antivirus software are not acceptable as protection for Windows operating systems. However, both the e-mail antivirus software and the operating system antivirus software can coexist and run on the same system.

Documentable Explanation: If another recognized antivirus product is installed and has a current signature file, this would still be a finding, but the severity code can be reduced to a Category III.
Fix Text (F-53829r1_fix)
Configure the system with supported, DoD-approved antivirus software. Ensure the signature file is current.