The McAfee VirusScan exclusions parameter is not configured as required.

From McAfee VirusScan Locally Configured Client

Part of DTAM050

Associated with IA controls: ECSC-1

Associated with: CCI-001241

SV-6723r2_rule The McAfee VirusScan exclusions parameter is not configured as required.

Vulnerability discussion

This parameter ensures that there are no unapproved exclusions from the virus scanning.

Check content

Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Network Associates\TVD\VirusScan Enterprise\ CurrentVersion\Tasks\{818C7543-358A-4C84-899A-14334EMS4BGS} Criteria: If the value is > 0 this is a finding. If the value is > 0, ensure the justification for exclusions found have been documented with the IAO/IAM. If exclusions are documented with the IAO/IAM, this is not a finding. If exclusions have not been documented, this is a finding.

Fix text

Change the registry key HKLM\Software\McAfee\DesktopProtection\Tasks\{21221C11-A06D-4558-B833-98E8C7 F6C4D2} so that the value of NumExcludeItems is 0. If not set to 0, all exclusions must be documented and approved with the IAO/IAM.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer