McAfee MOVE Agentless 3.6.1 Security Virtual Appliance STIG Version Comparison
McAfee MOVE Agentless 3.6.1 Security Virtual Appliance STIG
Comparison
There are 25 differences between versions v1 r3 (Oct. 23, 2015) (the "left" version) and v1 r5 (Oct. 28, 2016) (the "right" version).
Check AV-MOVE-SVA-001 was changed between these two versions. Green, underlined text was added, red, struck-out text was removed.
The regular view of the left check and right check may be easier to read.
Text Differences
Title
The McAfee MOVE AV Agentless SVA policy must be configured with, and managed by, the HBSS ePO server.
Check Content
NOTE: MOVE Agentless 3.0 3.61 Security Virtual Appliance (SVA) comes pre-installed with McAfee Agent 4.8 and requires that the McAfee Agent 4.8 Extension already be installed on the ePO 4.6 5.0.x Server. ePO 4.6 environments must upgrade to the McAfee Agent 4.8 Extension prior to deployment of the MOVE Agentless 3.0 3.61 SVA. From the ePO server console System Tree, select "My Organization". Select the Systems tab. To show all systems in the System Tree, select "This Group and All Subgroups" from the "Preset:" drop-down list. From the list of systems, locate the asset representing the McAfee MOVE Security Virtual Appliance (SVA). If the system designated as the McAfee MOVE Security Virtual Appliance (SVA) is not in the ePO server System Tree, this is a finding. If the system designated as the McAfee MOVE Security Virtual Appliance (SVA) is in the ePO server System Tree, click on the system to open the System Information page. On the System Information page, verify "MOVE AV [Agentless]" is listed as an Installed Product. If the system does not show MOVE AV [Agentless] listed as an installed product, this is a finding.
Discussion
Organizations should use centrally managed antivirus software that is controlled and monitored regularly by antivirus administrators, who are also typically responsible for acquiring, testing, approving, and delivering antivirus signature and software updates throughout the organization. Users should not be able to disable or delete antivirus software from their hosts, nor should they be able to alter critical settings. Antivirus administrators should perform continuous monitoring to confirm that hosts are using current antivirus software and that the software is configured properly. Implementing all of these recommendations should strongly support an organization in having a strong and consistent antivirus deployment across the organization.
Fix
Obtain the McAfee Agent install files from the McAfee ePO server and install onto the McAfee SVA, following the same procedures as for any other Linux system being managed by the McAfee ePO server. After installation, from the ePO server console System Tree, select "My Organization". Select the Systems tab. Find and double-click on the asset representing the McAfee MOVE Security Virtual Appliance (SVA) to open its properties. Under the "System System Information" section, verify Properties tab, ensure the "Last communication" Communication" date and time is within the time period designated by the "Agent-to-Server Communication Interval:" under the "McAfee McAfee Agent" Agent section. Under tab. Under the "System System information" section, verify Properties tab, next to the Installed Products field, ensure "MOVE MOVE AV [Agentless]" is listed as an installed product.