DTAVSEL-114 - The McAfee VirusScan Enterprise for Linux 1.9.x/2.0.x On-Demand scan must be configured to scan mounted volumes when mounted volumes point to a network server without an anti-virus solution installed.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

A server that functions as an attached disk drive is vulnerable if it is internally unprotected. Network attached storage (NAS) devices often have poor security. If they do not require any authentication, any infected device on the local network can grab confidential data from them or plant malicious files. To guard against malware on the network level, all devices must be taken into account. Any unprotected machine is a weakness for the whole network. It is imperative to protect Linux systems from malware introduced from mounted volumes pointing to network servers without an antivirus solution by ensuring they are scanned.

Solution

From the ePO server console System Tree, select 'My Organization'. Select the 'Systems' tab. To show all systems in the System Tree, select 'This Group and All Subgroups' from the 'Preset:' drop-down list.

From the list of systems, locate the asset representing the Linux system being reviewed. Click on the system to open the System Information page.

Click on Actions >> Agent >> Modify Tasks on a Single System.

From the list of available tasks in the 'Task Name' column, with the assistance of the ePO SA, identify the weekly On Demand scan client task.

If a weekly On Demand scan client task does not exist, this is a finding.

For the designated weekly On Demand scan client task, verify the 'Task Type' is listed as 'On Demand Scan'.
Verify the 'Status' is listed as 'Enabled'.
Under the 'Task Name' column, click on the link for the designated task to review the task properties.

In the 'Where' tab, in the 'Specify where scanning will take place', verify the all otherwise unprotected network servers to which this Linux system has mounted volumes is included.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_McAfee_VSEL_1-9_2-0_Managed_Client_STIG_V1R4_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CAT|II, CCI|CCI-001241, Rule-ID|SV-77551r3_rule, STIG-ID|DTAVSEL-114, Vuln-ID|V-63061

Plugin: Unix

Control ID: 1675a7f0c6a00b24ab4e302c97586e8d1bcbce23a392e15edad0b50e04753b4a