EX19-MB-000197 - Exchange software must be monitored for unauthorized changes.

Information

Monitoring software files for changes against a baseline on a regular basis may help detect the possible introduction of malicious code on a system.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Update the EDSP to specify that the organization monitors system files on servers for unauthorized changes against a baseline on a weekly basis or verify that this information is documented by the organization.

Monitor the software files (e.g., *.exe, *.bat, *.com, *.cmd, and *.dll) on Exchange servers for unauthorized changes against a baseline on a weekly basis.

Note: This can be done with the use of various monitoring tools.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Exchange_2019_Y24M10_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-5(1), CAT|II, CCI|CCI-001814, CCI|CCI-003938, Rule-ID|SV-259701r1015279_rule, STIG-ID|EX19-MB-000197, Vuln-ID|V-259701

Plugin: Windows

Control ID: 2f0a10f1da7632ed31e8ac3aa472b620515f6b310137aae347ab72bba062db72