STIGQter STIGQter: STIG Summary: Trend Micro Deep Security 9.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Feb 2016:

Trend Deep Security must scan all media used for system maintenance prior to use.

DISA Rule

SV-80395r1_rule

Vulnerability Number

V-65905

Group Title

SRG-APP-000073

Rule Version

TMDS-00-000055

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Trend Deep Security server to scan all media used for system maintenance prior to use.

The scope of Malware Scans can be controlled by editing the Malware Scan Configuration that is in effect on a computer. The Malware Scan Configuration determines which files and directories are included or excluded during a scan and which actions are taken if malware is detected on a computer (for example, clean, quarantine, or delete). There are two types of Malware Scan Configurations:
- Manual/Scheduled Scan Configurations
- Real-Time Scan Configurations

To enable Anti-Malware functionality on a computer:
Go to Computers.
Right-click a computer from the list of systems, select properties Anti-Malware >> General
Set Configuration to "On" or "Inherit On".

Check Contents

Review the Trend Deep Security server to ensure all media used for system maintenance is scanned prior to use.

Verify Anti-Malware is enabled on each server that is applicable to the accreditation boundary.

Go to Computers.
Right-click a computer from the list of systems, select properties Anti-Malware >> General
Verify Configuration is set to "On" or "Inherit On".

If Verify Configuration is set to "Off", this is a finding.

Vulnerability Number

V-65905

Documentable

False

Rule Version

TMDS-00-000055

Severity Override Guidance

Review the Trend Deep Security server to ensure all media used for system maintenance is scanned prior to use.

Verify Anti-Malware is enabled on each server that is applicable to the accreditation boundary.

Go to Computers.
Right-click a computer from the list of systems, select properties Anti-Malware >> General
Verify Configuration is set to "On" or "Inherit On".

If Verify Configuration is set to "Off", this is a finding.

Check Content Reference

M

Target Key

2955

Comments