Ensure that anti-virus software generates audit logs and the logs are properly retained |
This query polls the status of anti-virus software audit log configuration and verifies that the anti-virus is configured to generate audit logs and retain them according to PCI section 10.7. If any endpoints are not configured properly to generate antivirus logs or retain them, Action1 flags them as non-compliant and brings them to your attention.
Sign-up for Action1 Free Edition to receive real-time alerts and view instant data from your endpoints, such as alert on 5.2.d: Anti-virus Audit Logs are Enabled and Retained created, deleted or modified or run live or scheduled queries with the ability to export to CSV or Excel. Action1 Endpoint Security Platform is entirely SaaS, with online web interface (no management tools to install) and it has zero cost for basic functionality. Running in the Cloud, Action1 discovers all of your endpoints in seconds and you can query your entire network in plain English.
Endpoint configuration management in the Cloud
Manage endpoint configuration using plain English from the Cloud. Such as type 'Windows services' or 'reboot computer'.
Get results instantly from live systems and run automated actions.
Related Alerts and Reports:
5.2.b: Anti-virus Updates and Periodic Scans are Configured
Ensure that anti-virus software is configured for automatic updates and periodic scans
5.2.c: Anti-virus Definitions are Current and Periodic Scans are Performed
Ensure that anti-virus software has current virus definitions and periodic scans are actually performed
Find more information on 5.2.d: Anti-virus Audit Logs are Enabled and Retained at Microsoft TechNet.