Check: SRG-APP-000261-MAPP-NA
Mobile Application SRG:
SRG-APP-000261-MAPP-NA
(in version v1 r1)
Title
Applications that are utilized to address the issue of spam and provide protection from spam must automatically update any and all spam protection measures including signature definitions. (Cat II impact)
Discussion
Originators of spam emails are constantly changing their source email addresses in order to defeat spam countermeasures; therefore, spam software must be constantly updated to address the changing threat. A manual update procedure is labor intensive and does not scale well in an enterprise environment which necessitates an automatic update capability. Rationale for non-applicability: Enterprise email server functionality is not within the scope of the Mobile Applications SRG, which applies to single-user applications that do not provide server functionality to other hosts.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46981r1_rule
Vulnerability ID: V-35694
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001308 |
The information system automatically updates spam protection mechanisms. |
Controls
Number | Title |
---|---|
SI-8 (2) |
Automatic Updates |