STIGQter STIGQter: STIG Summary: McAfee MOVE Agentless 3.0 VSEL 1.9 for SVA STIG Version: 1 Release: 3 Benchmark Date: 23 Oct 2015: The antivirus signature file age must not exceed 7 days.

DISA Rule

SV-61873r1_rule

Vulnerability Number

V-48995

Group Title

DTAVSEL-001 McAfee MOVE Agentless antivirus signature age

Rule Version

DTAVSEL-001

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

From the ePO server console System Tree, select "My Organization". Select the "Systems" tab. To show all systems in the System Tree, select "This Group and All Subgroups" from the "Preset:" drop-down list. From the list of systems, locate the asset representing the McAfee MOVE Security Virtual Appliance (SVA). Click on the system to open the System Information page.

Click on Actions | Agent | Modify Tasks on a Single System.

On the Client Tasks page, click on Actions | New Client Task Assignment.

On the Client Task Assignment Builder page, under the "Product" section, select "McAfee Agent".
Under the "Task Type" section, select "Product Update".
Under the "Task Name" section, click on "Create New Task".

Type a unique name for the "Task Name".
For "Package selection:", select the "All packages" radio button. Click Save.

Or, select the "Selected packages" radio button.
For the "Package types:" section, select the "DAT" check box and the "Linux Engine" check box under the "Signatures and engines:" section.
Click Save.

On the Client Task Assignment Builder page, under the "Task Name" section, select the task just created.
Click on "Next" to schedule the task.
For "Schedule status:", select the radio button for "Enabled".
For "Schedule type:", choose "Daily".
Schedule the "Effective period:", "Start time:" and other options according to best practices.
Click Next to view Summary.
Click Save.

Check Contents

From the ePO server console System Tree, select "My Organization". Select the "Systems" tab. To show all systems in the System Tree, select "This Group and All Subgroups" from the "Preset:" drop-down list. From the list of systems, locate the asset representing the McAfee MOVE Security Virtual Appliance (SVA). Click on the system to open the System Information page.

On the System Information page, select the "Products" tab. Under the Product section, select "VirusScan Enterprise for Linux".
Scroll down locate the DAT Date and DAT Version.

Verify the "DAT Date:" is within the last 7 days.

If the "DAT Date:" is not within the last 7 days, this is a finding.

Vulnerability Number

V-48995

Documentable

False

Rule Version

DTAVSEL-001

Severity Override Guidance

From the ePO server console System Tree, select "My Organization". Select the "Systems" tab. To show all systems in the System Tree, select "This Group and All Subgroups" from the "Preset:" drop-down list. From the list of systems, locate the asset representing the McAfee MOVE Security Virtual Appliance (SVA). Click on the system to open the System Information page.

On the System Information page, select the "Products" tab. Under the Product section, select "VirusScan Enterprise for Linux".
Scroll down locate the DAT Date and DAT Version.

Verify the "DAT Date:" is within the last 7 days.

If the "DAT Date:" is not within the last 7 days, this is a finding.

Check Content Reference

M

Responsibility

System Administrator

Target Key

2580

Comments