CCI-001242
The organization configures malicious code protection mechanisms to perform real-time scans of files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy.
The CA API Gateway providing content filtering must be configured to perform real-time scans of files from external sources at network entry/exit points as they are downloaded and prior to being opened or executed.
1 rule found Severity: Medium

Microsoft Defender AV must be configured to run and scan for malware and other potentially unwanted software.
1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Firefox must be configured to not automatically execute or download MIME types that are not authorized for auto-download.
1 rule found Severity: Medium

Microsoft Defender AV must be configured to check in real time with MAPS before content is run or accessed.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

A DoD-approved third party Exchange-aware malicious code protection application must be implemented.
2 rules found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium
