4.2.5 Enable grayware detection on antivirus

Information

Grayware detection should be enabled.

Rationale:

Usage of grayware is generally not allowed in strict company policies and some graywares can be used for malicious intent. If the file passes the virus scan, it can be checked for grayware. Grayware signatures are kept up to date in the same manner as the antivirus definitions.

Solution

On CLI:

FGT1 # config antivirus settings
FGT1 (settings) # set grayware enable

Default Value:

Enabled

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1, CSCv7|8.2

Plugin: FortiGate

Control ID: e66f8ddd3bf5e21db229d8899c87cccb668133e0a29b0b65f2cf0f60eb9b2094