STIGQter STIGQter: STIG Summary: Microsoft Exchange 2016 Mailbox Server Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

Exchange servers must have an approved DoD email-aware virus protection software installed.

DISA Rule

SV-228397r612748_rule

Vulnerability Number

V-228397

Group Title

SRG-APP-000261

Rule Version

EX16-MB-000530

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Update the EDSP to specify the organization's anti-virus strategy.

Install and configure a DoD-approved compatible Exchange 2016 email-aware anti-virus scanner product.

Check Contents

Review the Email Domain Security Plan (EDSP).

Determine the anti-virus strategy.

Verify the email-aware anti-virus scanner product is Exchange 2016 compatible and DoD approved.

If email servers are using an email-aware anti-virus scanner product that is not DoD approved and Exchange 2016 compatible, this is a finding.

Vulnerability Number

V-228397

Documentable

False

Rule Version

EX16-MB-000530

Severity Override Guidance

Review the Email Domain Security Plan (EDSP).

Determine the anti-virus strategy.

Verify the email-aware anti-virus scanner product is Exchange 2016 compatible and DoD approved.

If email servers are using an email-aware anti-virus scanner product that is not DoD approved and Exchange 2016 compatible, this is a finding.

Check Content Reference

M

Target Key

4223

Comments