1.13.6 Ensure 'Specify the day of the week to run a scheduled scan' is set to 'Enabled: 0' or higher, but not '8'

Information

This policy setting configures the day of the week to perform a scheduled scan.

The recommended state for this setting is: Enabled: 0 or higher, but not 8.

This setting can be configured with the following values:

- (0x0) Every Day
- (0x1) Sunday
- (0x2) Monday
- (0x3) Tuesday
- (0x4) Wednesday
- (0x5) Thursday
- (0x6) Friday
- (0x7) Saturday
- (0x8) Never (default)

Performing a scheduled scan at least once a week is a consistent way to verify that critical parts of the system remain clean.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled: 0 or higher, but not 8 :

Computer Configuration\Policies\Administrative Templates\Windows Components\Microsoft Defender Antivirus\Scan\Specify the day of the week to run a scheduled scan

Note: This Group Policy path is provided by the Group Policy template WindowsDefender.admx/adml that is included with the Microsoft Windows 8.1 and Server 2012 R2 Administrative Templates (or newer).

Impact:

If Quick Scans are used for the scheduled scan type, this setting is not expected to negatively affect system performance, as these scans are intentionally designed to be lightweight.

If Full Scans are used for the scheduled scan type, this may impact system performance as a full scan comprehensively scans every file, folder, running process, and system area on the device.

See Also

https://workbench.cisecurity.org/benchmarks/25919

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: a6c7b805ee67a961d3cb2ffb10d886d730ae20843ec9acfa1695e396d72464c6