SV-93245r1_rule
V-78539
MV45-OAS-000008
MV45-OAS-000008
CAT II
10
Access the McAfee ePO console.
Select Menu >> Policy >> Policy Catalog and then select "MOVE AntiVirus 4.5.0" from the Product list.
From the Category list, select "On Access Scan".
Select each configured On Access Scan policy.
Under "Exclusions", remove any Process Exclusions that have been configured other than the following:
%WINDIR%\system32\mssearch.exe
UserProfileManager.exe
%WINDIR%\system32\searchindexer.exe
%WINDIR%\system32\mssdmn.exe
%WINDIR%\system32\winfs\winfs.exe
%WINDIR%\system32\mssfh.exe
Click "Save".
Access the McAfee ePO console.
Select Menu >> Policy >> Policy Catalog and then select "MOVE AntiVirus 4.5.0" from the Product list.
From the Category list, select "On Access Scan".
Select each configured On Access Scan policy.
Under "Exclusions", verify no Process Exclusions have been configured other than the following:
%WINDIR%\system32\mssearch.exe
UserProfileManager.exe
%WINDIR%\system32\searchindexer.exe
%WINDIR%\system32\mssdmn.exe
%WINDIR%\system32\winfs\winfs.exe
%WINDIR%\system32\mssfh.exe
If any Process Exclusions are configured and those Process Exclusions have not been formally documented by the System Administrator and approved by the ISSO/ISSM, this is a finding.
V-78539
False
MV45-OAS-000008
Access the McAfee ePO console.
Select Menu >> Policy >> Policy Catalog and then select "MOVE AntiVirus 4.5.0" from the Product list.
From the Category list, select "On Access Scan".
Select each configured On Access Scan policy.
Under "Exclusions", verify no Process Exclusions have been configured other than the following:
%WINDIR%\system32\mssearch.exe
UserProfileManager.exe
%WINDIR%\system32\searchindexer.exe
%WINDIR%\system32\mssdmn.exe
%WINDIR%\system32\winfs\winfs.exe
%WINDIR%\system32\mssfh.exe
If any Process Exclusions are configured and those Process Exclusions have not been formally documented by the System Administrator and approved by the ISSO/ISSM, this is a finding.
M
3233