Check: BROM-00-000245
Bromium Secure Platform 4.x STIG:
BROM-00-000245
(in version v1 r1)
Title
The Bromium Enterprise Controller (BEC) must protect the BEC Web Console from unauthorized access. (Cat II impact)
Discussion
Protecting audit data also includes identifying and protecting the tools used to view and manipulate log data. Therefore, protecting audit tools is necessary to prevent unauthorized operation on audit data. The BEC Web console can gives a view of events, threat conditions, policies, and client information and thus is considered an audit tool. BEC does not allow the integration of other audit tool provided by third-party vendors. The BEC Web console access is configured in Settings >> Users.
Check Content
Obtain a list of authorized BEC Web console users from the site representative. Verify only these users are configured for access. 1. From the BEC console, click on "Settings". 2. View the list of Users. If unauthorized users are listed in the BEC Web console, this is a finding.
Fix Text
Configure BEC Web console access to permit only authorized users. 1. From the BEC console, click on "Settings". 2. Select "Users". 3. Click User Options >> Add User. 4. Add new user and their Active Directory details, and assign new user to a Group using the drop-down list.
Additional Identifiers
Rule ID: SV-95135r1_rule
Vulnerability ID: V-80431
Group Title: SRG-APP-000121
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001493 |
The information system protects audit tools from unauthorized access. |
Controls
Number | Title |
---|---|
AU-9 |
Protection Of Audit Information |