Rules Related To 'mcafee'

Component overview

Relevant packages:

Relevant groups:

Changelog:

No changes recorded.

Relevant rules:

Rule details

Ensure McAfee Endpoint Security for Linux (ENSL) is running

agent_mfetpd_running

Description

Install McAfee Endpoint Security for Linux antivirus software which is provided for DoD systems and uses signatures to search for the presence of viruses on the filesystem.

Rationale

Virus scanning software can be used to detect if a system has been compromised by computer viruses, as well as to limit their spread to other systems.

Install McAfee Virus Scanning Software

install_mcafee_antivirus

Description

Install McAfee VirusScan Enterprise for Linux antivirus software which is provided for DoD systems and uses signatures to search for the presence of viruses on the filesystem.

Rationale

Virus scanning software can be used to detect if a system has been compromised by computer viruses, as well as to limit their spread to other systems.

Install the McAfee Runtime Libraries and Linux Agent

install_mcafee_cma_rt

Description

Install the McAfee Runtime Libraries (MFErt) and Linux Agent (MFEcma).

Rationale

The McAfee Runtime Libraries (MFErt) and Linux Agent (MFEcma) are dependencies for VirusScan Enterprise for Linux (VSEL) and Host-based Security System (HBSS) to run.

Install the Asset Configuration Compliance Module (ACCM)

install_mcafee_hbss_accm

Description

Install the Asset Configuration Compliance Module (ACCM).

Rationale

Without a host-based intrusion detection tool, there is no system-level defense when an intruder gains access to a system or network. Additionally, a host-based intrusion prevention tool can provide methods to immediately lock out detected intrusion attempts.

Install the Policy Auditor (PA) Module

install_mcafee_hbss_pa

Description

Install the Policy Auditor (PA) Module.

Rationale

Without a host-based intrusion detection tool, there is no system-level defense when an intruder gains access to a system or network. Additionally, a host-based intrusion prevention tool can provide methods to immediately lock out detected intrusion attempts.

Virus Scanning Software Definitions Are Updated

mcafee_antivirus_definitions_updated

Description

Ensure virus definition files are no older than 7 days or their last release.

Rationale

Virus scanning software can be used to detect if a system has been compromised by computer viruses, as well as to limit their spread to other systems.

Install the Host Intrusion Prevention System (HIPS) Module

package_MFEhiplsm_installed

Description

Install the McAfee Host Intrusion Prevention System (HIPS) Module if it is absolutely necessary. If SELinux is enabled, do not install or enable this module.

Rationale

Without a host-based intrusion detection tool, there is no system-level defense when an intruder gains access to a system or network. Additionally, a host-based intrusion prevention tool can provide methods to immediately lock out detected intrusion attempts.

Install McAfee Endpoint Security for Linux (ENSL)

package_mcafeetp_installed

Description

Install McAfee Endpoint Security for Linux antivirus software which is provided for DoD systems and uses signatures to search for the presence of viruses on the filesystem. The McAfeeTP package can be installed with the following command:

$ sudo yum install McAfeeTP

Rationale

Virus scanning software can be used to detect if a system has been compromised by computer viruses, as well as to limit their spread to other systems.

Enable nails Service

service_nails_enabled

Description

The nails service is used to run McAfee VirusScan Enterprise for Linux and McAfee Host-based Security System (HBSS) services. The nails service can be enabled with the following command:

$ sudo systemctl enable nails.service

Rationale

Virus scanning software can be used to detect if a system has been compromised by computer viruses, as well as to limit their spread to other systems.