CCI-001245
CCI-001245 Definition
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed configures the information system to address the receipt of false positives during malicious code detection and eradication, and the resulting potential impact on the availability of the information system. For information system components that have applicable STIGs or SRGs, the organization being inspected/assessed must comply with the STIG/SRG guidance that pertains to CCI 1245.
Validation Procedures
The organization conducting the inspection/assessment examines the information system to ensure the organization being inspected/assessed configures the information system to address the receipt of false positives during malicious code detection and eradication, and the resulting potential impact on the availability of the information system. For information system components that have applicable STIGs or SRGs, the organization conducting the inspection/assessment evaluates the components to ensure that the organization being inspected/assessed has configured the information system in compliance with the applicable STIGs and SRGs pertaining to CCI 1245.
Compelling Evidence
1.) Signed and dated system security plan with reference section pertaining to how malicious code is blocked and quarantined in near-real time frequency (DoD recommendation) and defines who are the administrators who are responsible for responding to alerts generated from malicious code intrusion attempts. 2.) Complete protection software logs. 3.) Message logs. 4.) Applicable STIG/SRG checks pertaining to CCI 1245.