The Cisco ISE must verify anti-malware software is installed and up to date on posture required clients defined in the NAC System Security Plan (SSP) prior to granting trusted network access. This is required for compliance with C2C Step 4.
<VulnDiscussion>New viruses and malware are consistently being discovered. If the host-based security software is not current then it will not be able to defend against exploits that have been previously discovered.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
If required by the NAC SSP, configure the posture policy to verify that an anti-malware software is up to date.
1. Navigate to Work Centers >> Posture >> Policy Elements.
2. Create Anti-Malware Condition.
a. Expand "Conditions" on the left of the page.
b. Choose "Anti-Malware".
c. Choose "Add".
d. Define a Name.
e. Select the Operating System.
f. Select the vendor.
g. Check "Definition".
h. Check "Check against latest AV definition file version if available. Otherwise check against latest definition file date." or "Allow virus definition file to be (<1) days older than the current system date."
i. Select the desired product/products.
j. Choose "Submit".
3. Create Anti-Malware Remediation.
a. Expand "Remediation's" on the left of the page.
b. Choose "Anti-Malware".
c. Choose "Add".
d. Define a Name.
e. Select the Operating System.
f. Select the Remediation Type.
g. Define the interval between retries.
h. Define Retry Count.
i. Select the desired Vendor Name.
j. Check "Remediation Option is to enable the Firewall".
k. Select the Product Name.
l. Choose "Submit".
4. Edit the Posture Policy.
a. Navigate to Work Centers >> Posture >> Posture Policy.
b. Find the Posture Policy that will be applied to the posture required endpoints.
c. Select the Requirement ensuring there is a green check box to the left of the name indicating it is a mandatory requirement.
d. Choose "Done".
e. Choose "Save".
Note: If any other Definition option is used, the Posture Updates must be updated (Navigate to Work Centers >> Posture >> Settings >> Software Updates >> Posture Updates).
Configure the posture policy to verify that an anti-malware software is installed.
1. Navigate to Work Centers >> Posture >> Policy Elements.
2. Create Anti-Malware Condition.
a. Expand "Conditions" on the left of the page.
b. Choose "Anti-Malware".
c. Choose "Add".
d. Define a Name.
e. Select the Operating System.
f. Select the vendor.
g. Check "Installation".
h. Select the desired product/products.
i. Choose "Submit".
3. Create Anti-Malware Remediation.
a. Expand "Remediation's" on the left of the page.
b. Choose "Anti-Malware".
c. Choose "Add".
d. Define a Name.
e. Select the Operating System.
f. Select the Remediation Type.
g. Define the interval between retries.
h. Define Retry Count.
i. Select the desired Vendor Name.
j. Check "Remediation Option is to enable the Firewall".
k. Select the Product Name.
l. Choose "Submit".
4. Edit the Posture Policy.
a. Navigate to Work Centers >> Posture >> Posture Policy.
b. Find the Posture Policy that will be applied to the posture required endpoints.
c. Select the Requirement ensuring there is a green check box to the left of the name indicating it is a mandatory requirement.
d. Choose "Done".
e. Choose "Save".