2.1 Ensure 'Block File Types' is configured to match the enterprise blacklist

Information

A common tactic of malware is to identify the type of malicious code protection software running on the system and deactivate it. Malicious code includes viruses, worms, Trojan horses, and Spyware.
Rationale:
Malicious code protection software must be protected to prevent a non-privileged user or malicious piece of software from disabling the protection mechanism.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Navigate to Central Administration.
1. Click Security, and then click Define blocked file type.
2. To change the web application, click the link next to Web Application: and then click Change Web Application.
3. In the Select Web Application dialog, click an app.
4. On the Blocked File Types page to add a file to block, type a file extension (with the period), one per line.
5. Add all file types listed in the enterprise blacklist.
6. Repeat check for each web application.

See Also

https://workbench.cisecurity.org/files/2031

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(3), CSCv6|8

Plugin: Windows

Control ID: 52c1e2f757e8feb29a33d08aff00a6fe9ac2eb9d4f80919e75e320dc94146d18