This document describes whether antivirus scanning remains necessary after attachment removal on Cisco Email Security Appliance (ESA).
Antivirus scanning must remain enabled on the Cisco Email Security Appliance (ESA) even when attachment-dropping rules are enabled, because attachment removal does not reliably remove all malicious content from every message structure.
Administrators can assume that removing attachments eliminates malware risk and makes antivirus scanning unnecessary. This document explains why antivirus scanning must still be used after attachment removal.
This guidance applies to inbound and outbound email messages processed by the Cisco Email Security Appliance (ESA).
Antivirus scanning is required for messages even when attachment-dropping rules are enabled on the Cisco Email Security Appliance (ESA).
Keep antivirus scanning enabled for all applicable mail flows after attachment removal policies are configured.
Note: Expected outcome: attachment removal can reduce exposure to some file-based threats, but antivirus scanning is still needed to detect malicious content that remains in the message. Scope: this guidance addresses whether antivirus scanning is still required after attachment removal; it does not describe all malware detection features on ESA.
Attachment dropping reduces risk but does not eliminate it.
For more information, see:
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
24-Jun-2014
|
Initial Release |