Skip to content

The Palo Alto Networks security platform must enable Antivirus, Anti-spyware, and Vulnerability Protection for all authorized traffic.

An XCCDF Rule

Description

The flow of all communications traffic must be monitored and controlled so it does not introduce any unacceptable risk to the network infrastructure or data. Restricting the flow of communications traffic, also known as Information flow control, regulates where information is allowed to travel as opposed to who is allowed to access the information and without explicit regard to subsequent accesses to that information. Traffic that is prohibited by the PPSM and Vulnerability Assessments must be denied by the policies configured in the Palo Alto Networks security platform; this is addressed in a separate requirement. Traffic that is allowed by the PPSM and Vulnerability Assessments must still be inspected by the IDPS capabilities of the Palo Alto Networks security platform known as Content-ID. Content-ID is enabled on a per rule basis using individual or group profiles to facilitate policy-based control over content traversing the network.

ID
SV-207688r557390_rule
Version
PANW-IP-000001
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure an Antivirus Profile, an Anti-spyware Profile, and a Vulnerability Protection Profile in turn.  Use these Profiles in the Security Policy or Policies that allows authorized traffic.
To create an Antivirus Profile:
Go to Objects >> Security Profiles >> Antivirus
Select "Add".
In the "Antivirus Profile" window,  complete the required fields.
Complete the "Name" and "Description" fields.