4.1 Ensure 'Antivirus Update Schedule' is set to download and install updates hourly

Information

Set Antivirus Update Schedule to download and install updates hourly.
Rationale:
New antivirus definitions may be released at any time. With an hourly update schedule, the firewall can ensure threats with new definitions are quickly mitigated. A daily update schedule could leave an organization vulnerable to a known virus for nearly 24 hours, in a worst-case scenario. Setting an appropriate threshold value reduces the risk of a bad definition file negatively affecting traffic.

Solution

Navigate to Device > Dynamic Updates > Antivirus Update Schedule.
Set Action to Download and Install.
Set Recurrence to Hourly.
or
To remediate these settings, execute the following CLI commands:
username@hostname#set deviceconfig system update-schedule anti-virus recurring daily at WX:YZ
username@hostname#set deviceconfig system update-schedule anti-virus recurring daily action download-and-install
Default Value:
Not Configured

See Also

https://workbench.cisecurity.org/files/1780

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3(2)

Plugin: Palo_Alto

Control ID: 393e9bea26bf83f19891ab824a3ec30654f78fd00f0cffaaf94188211bb803cf