Skip to content

The Cisco ISE must verify anti-malware software is installed and up to date on posture required clients defined in the NAC System Security Plan (SSP) prior to granting trusted network access. This is required for compliance with C2C Step 4.

An XCCDF Rule

Description

<VulnDiscussion>New viruses and malware are consistently being discovered. If the host-based security software is not current then it will not be able to defend against exploits that have been previously discovered.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-242579r812740_rule
Severity
High
References
Updated



Remediation - Manual Procedure

If required by the NAC SSP, configure the posture policy to verify that an anti-malware software is up to date.

1. Navigate to Work Centers >> Posture >> Policy Elements.

2. Create Anti-Malware Condition.
a. Expand "Conditions" on the left of the page.