3.11.5.2 (L1) Ensure 'Notify antivirus programs when opening attachments (User)' is set to 'Enabled'

Information

This policy setting manages the behavior for notifying registered antivirus programs. If multiple programs are registered, they will all be notified.

The recommended state for this setting is: Enabled

Note: An updated antivirus program must be installed for this policy setting to function properly.

Antivirus programs that do not perform on-access checks may not be able to scan downloaded files.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled

Administrative Templates\Windows Components\Attachment Manager\Notify antivirus programs when opening attachments (User)

Impact:

Windows tells the registered antivirus program(s) to scan the file when a user opens a file attachment. If the antivirus program fails, the attachment is blocked from being opened.

See Also

https://workbench.cisecurity.org/benchmarks/16852

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: 3502db9369dde5f3df8e9cc125216f98c4d753d410e594859c9d6d87fdc28449