Check: EX16-ED-000380
Microsoft Exchange 2016 Edge Transport Server STIG:
EX16-ED-000380
(in versions v2 r5 through v1 r4)
Title
The Exchange Sender Reputation filter must be enabled. (Cat II impact)
Discussion
By performing filtering at the perimeter, up to 90 percent of spam, malware, and other undesirable messages are eliminated from the message stream rather than admitting them into the mail server environment. Sender Reputation is antispam functionality that blocks messages according to many characteristics of the sender. Sender Reputation relies on persisted data about the sender to determine what action, if any, to take on an inbound message. This setting enables the Sender Reputation function.
Check Content
Note: If third-party anti-spam product is being used, the anti-spam product must be configured to meet the requirement. Open the Exchange Management Shell and enter the following command: Get-SenderReputationConfig | Select Name, Enabled If the value of "Enabled" is not set to "True", this is a finding.
Fix Text
Open the Exchange Management Shell and enter the following command: Set-SenderReputationConfig -Enabled $true
Additional Identifiers
Rule ID: SV-221237r879653_rule
Vulnerability ID: V-221237
Group Title: SRG-APP-000261
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001308 |
The information system automatically updates spam protection mechanisms. |
Controls
Number | Title |
---|---|
SI-8 (2) |
Automatic Updates |