Skip to content

Vendor supported, DOD approved, anti-virus software is not installed and configured on all SAN servers in accordance with the applicable operating system STIG on SAN servers and management devices and kept up-to-date with the most recent virus definition tables.

An XCCDF Rule

Description

The SAN servers and other hosts are subject to virus and worm attacks as are any systems running an OS. If the anti-virus software is not installed or the virus definitions are not maintained on these systems, this could expose the entire enclave network to exploits of known vulnerabilities. The IAO/NSO will ensure that vendor supported, DOD approved, anti-virus software is installed and configured on all SAN servers in accordance with the applicable operating system STIG on SAN servers and management devices and kept up-to-date with the most recent virus definition tables.

Property Value
Responsibility Information Assurance Officer

ID
SV-6743r1_rule
Version
SAN04.006.00
Severity
High
Updated

Remediation Templates

A Manual Procedure

Install and correctly configure a DOD approved anti-virus.