5.9 Ensure the Malware Detections report is reviewed at least weekly

Information

You should review the Malware Detections report at least weekly. This report shows specific instances of Microsoft blocking a malware attachment from reaching your users.

Rationale:

While this report isn't strictly actionable, reviewing it will give you a sense of the overall volume of malware being targeted at your users, which may prompt you to adopt more aggressive malware mitigations.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To review the report, use the Microsoft 365 Admin Center:

Select Security (also at https://protection.office.com).

Expand Reports then select Dashboard.

Review the Malware Detected in Email report.

See Also

https://workbench.cisecurity.org/files/3433