Society of Payment Security Professionals Forum  

Go Back   Society of Payment Security Professionals Forum > Discussion Groups > PCI DSS Q&A

Reply
 
Thread Tools Display Modes
  #1  
Old 02-10-2009, 02:59 AM
FunPolice FunPolice is offline
Member
 
Join Date: Aug 2007
Posts: 43
Default 5.2 - "actively running"

Hello,

I was just wondering if anyone had any thoughts on requirement 5.2 and AV being "actively running." Do people take this as meaning that on-load protection has been enabled? I'm looking at web servers in particular, and issues around performance. While I'm also looking at a Fortinet network AV solution, I was wondering if people always insisted on on-load functionality being enabled for items like web servers.

Speaking of which, if anyone has any comments on the Fortinet AV capabilities, I'm all ears.

Cheers,
fp
Reply With Quote
  #2  
Old 02-10-2009, 02:38 PM
jbhall56's Avatar
jbhall56 jbhall56 is online now
Senior Member
 
Join Date: Feb 2007
Location: Minneapolis, MN
Posts: 1,277
Default

Active scanning means that files are scanned for viruses whenever they are processed, i.e., opened/closed, read/written, etc.

As for Fortinet, I'm not fully versed on it. However, my understanding is that it is an appliance solution that monitors email, FTP and similar traffic and looks for viruses in the payloads of these protocols. It does not provide protection for systems that could be infected from a CD/DVD or other methods outside its purview. That is why it is only part of the solution in my book. You still need anti-virus on your servers and workstations for full protection.
__________________
Jeff Hall, Director, Risk Advisory Services
RSM McGladrey Inc
801 Nicollet Mall, 11th Floor, West Tower
Minneapolis, MN 55402-2526
612 376 9280 - office
612 395 7280 - facsimile
www.mcgladrey.com

The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc
Reply With Quote
  #3  
Old 02-11-2009, 07:38 AM
mckafka99 mckafka99 is offline
Junior Member
 
Join Date: Mar 2008
Posts: 14
Default

Quote:
Originally Posted by FunPolice View Post
While I'm also looking at a Fortinet network AV solution, I was wondering if people always insisted on on-load functionality being enabled for items like web servers.

Speaking of which, if anyone has any comments on the Fortinet AV capabilities, I'm all ears.

Cheers,
fp
Fortinet produces a line of Unified Threat Management devices that provide inline Network based protection of a number of things such as AV, IPS/IDS, Web Filtering, Spam Filtering, content filtering, etc. These come as a subscription service. We use a Fortigate 300A as our perimeter device and I have found good success with it

From a host based perspective, Fortinet also offers the "FortiClient". However, I do not have any experience with that product.
Reply With Quote
Reply

Tags
5.2, actively running, antivirus

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 05:07 AM.


Copyright (c) The Aegenis Group, Inc.