STIGQter STIGQter: STIG Summary: McAfee VirusScan 8.8 Managed Client STIG Version: 5 Release: 21 Benchmark Date: 25 Oct 2019:

The antivirus signature file age must not exceed 7 days.

DISA Rule

SV-55133r2_rule

Vulnerability Number

V-19910

Group Title

DTAG008 - The antivirus signature file age exceeds 7 days.

Rule Version

DTAG008

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Update client machines via ePO client task. If this fails to update the client, update antivirus signature files as your local process describes (e.g., auto update or runtime executable.)

Check Contents

Guidance in DTAM016 requires updates be run daily, automatically or manually. If compliant, the DAT date will be within 24-48 hours old. Since automated update tasks’ success is not guaranteed, the expectation is for update task success to be frequently monitored and corrected when unsuccessful. To allow for that correction, the minimum acceptable threshold for DAT date is not to exceed 7 days.

On the client machine, right-click on the McAfee red shield icon in the taskbar.

Choose "About".

Scroll down to the "McAfee VirusScan Enterprise + AntiSpyware Enterprise" section.

Review the date for "DAT Created On:".

Criteria: If the "DAT Created On:" date is older than 7 days from the current date, this is a finding.

From the ePO server console System Tree, select the "Systems" tab, select the asset to be checked, and double-click to open its properties. Under the System Information, scroll down to the VirusScan Enterprise section and click on the "More" link in the top-right portion of the VirusScan Enterprise section. Scroll down to the General section and confirm the DAT Date reflected is within the last 7 days.

Criteria: If the DAT Date is older than 7 days from the current date, this is a finding.

NOTE: If the vendor or trusted site's files are also older than 7 days and match the date of the signature files on the machine, this is not a finding.

Vulnerability Number

V-19910

Documentable

False

Rule Version

DTAG008

Severity Override Guidance

Guidance in DTAM016 requires updates be run daily, automatically or manually. If compliant, the DAT date will be within 24-48 hours old. Since automated update tasks’ success is not guaranteed, the expectation is for update task success to be frequently monitored and corrected when unsuccessful. To allow for that correction, the minimum acceptable threshold for DAT date is not to exceed 7 days.

On the client machine, right-click on the McAfee red shield icon in the taskbar.

Choose "About".

Scroll down to the "McAfee VirusScan Enterprise + AntiSpyware Enterprise" section.

Review the date for "DAT Created On:".

Criteria: If the "DAT Created On:" date is older than 7 days from the current date, this is a finding.

From the ePO server console System Tree, select the "Systems" tab, select the asset to be checked, and double-click to open its properties. Under the System Information, scroll down to the VirusScan Enterprise section and click on the "More" link in the top-right portion of the VirusScan Enterprise section. Scroll down to the General section and confirm the DAT Date reflected is within the last 7 days.

Criteria: If the DAT Date is older than 7 days from the current date, this is a finding.

NOTE: If the vendor or trusted site's files are also older than 7 days and match the date of the signature files on the machine, this is not a finding.

Check Content Reference

M

Responsibility

System Administrator

Target Key

2266

Comments