STIGQter STIGQter: STIG Summary: Microsoft Exchange 2019 Mailbox Server Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

Exchange servers must have an approved DOD email-aware virus protection software installed.

DISA Rule

SV-259686r961161_rule

Vulnerability Number

V-259686

Group Title

SRG-APP-000261

Rule Version

EX19-MB-000134

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Update the EDSP to specify the organization's antivirus strategy.

Install and configure a DOD-approved compatible Exchange 2019 email-aware antivirus scanner product.

Check Contents

Review the Email Domain Security Plan (EDSP).

Determine the antivirus strategy.

Verify the email-aware antivirus scanner product is Exchange 2019 compatible and DOD approved.

If email servers are using an email-aware antivirus scanner product that is not DOD approved and Exchange 2019 compatible, this is a finding.

Vulnerability Number

V-259686

Documentable

False

Rule Version

EX19-MB-000134

Severity Override Guidance

Review the Email Domain Security Plan (EDSP).

Determine the antivirus strategy.

Verify the email-aware antivirus scanner product is Exchange 2019 compatible and DOD approved.

If email servers are using an email-aware antivirus scanner product that is not DOD approved and Exchange 2019 compatible, this is a finding.

Check Content Reference

M

Target Key

5580