3.5 Ensure that SharePoint specific malware (i.e. anti-virus) protection software is integrated and configured - Attempt to clean

Information

SharePoint-specific malware (i.e. anti-virus) protection software must be integrated and
configured.

Rationale:

Configuring anti-virus settings ensures documents will be scanned for viruses upon
download from and upload to the SharePoint server. Anti-virus settings are not configured
by default, therefore leaving the documents downloaded from or uploaded to SharePoint
open to potential malware.

Solution

1. Log on to the Central Administration website.
2. Navigate to Security > Manage antivirus settings.
3. SharePoint specific malware (i.e. anti-virus) protection software must be integrated
and configured for each of the following:
o Scan documents on upload.
o Scan documents on download.
o Attempt to clean infected documents.

See Also

https://workbench.cisecurity.org/files/2395

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AU-3, 800-53|SI-3, 800-53|SI-5, CSCv6|8.1, CSCv7|8.1, CSCv7|8.6

Plugin: Windows

Control ID: e193c029810877a88588c8c013bf7ef1949afcd912cc5f914c4920691745eb4d