EX16-MB-000530 - Exchange servers must have an approved DoD email-aware virus protection software installed.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

With the proliferation of trojans, viruses, and spam attaching themselves to email messages (or attachments), it is necessary to have capable email-aware anti-virus (AV) products to scan messages and identify any resident malware. Because email messages and their attachments are formatted to the MIME standard, a flat-file AV scanning engine is not suitable for scanning email message stores.

Email-aware anti-virus engines must be Exchange 2016 compliant. Competent email scanners will have the ability to scan mail stores, attachments (including zip or other archive files) and mail queues and to issue warnings or alerts if malware is detected. As with other AV products, a necessary feature to include is the ability for automatic updates.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Update the EDSP to specify the organization's anti-virus strategy.

Install and configure a DoD-approved compatible Exchange 2016 email-aware anti-virus scanner product.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Exchange_2016_Y22M07_STIG.zip

Item Details

References: CAT|I, CCI|CCI-001308, Rule-ID|SV-228397r612748_rule, STIG-ID|EX16-MB-000530, STIG-Legacy|SV-95419, STIG-Legacy|V-80709, Vuln-ID|V-228397

Plugin: Windows

Control ID: 439e0e5ebf083e3c525426009eab88fd069fe54d9ae126ee751bab17dd3a4df1