STIGQter STIGQter: STIG Summary: Microsoft Exchange 2013 Mailbox Server Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 22 Jan 2021:

Exchange servers must have an approved DoD email-aware virus protection software installed.

DISA Rule

SV-207319r615936_rule

Vulnerability Number

V-207319

Group Title

SRG-APP-000261

Rule Version

EX13-MB-000265

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Update the EDSP.

Install and configure a DoD-approved compatible Exchange 2013 email-aware antivirus scanner product.

Check Contents

Review the Email Domain Security Plan (EDSP).

Determine the antivirus strategy.

Verify the email-aware antivirus scanner product is Exchange 2013 compatible and DoD-approved.

If email servers are using an email-aware antivirus scanner product that is not DoD-approved and Exchange 2013 compatible, this is a finding.

Vulnerability Number

V-207319

Documentable

False

Rule Version

EX13-MB-000265

Severity Override Guidance

Review the Email Domain Security Plan (EDSP).

Determine the antivirus strategy.

Verify the email-aware antivirus scanner product is Exchange 2013 compatible and DoD-approved.

If email servers are using an email-aware antivirus scanner product that is not DoD-approved and Exchange 2013 compatible, this is a finding.

Check Content Reference

M

Target Key

2923

Comments