Check: ENS-FW-000008
Trellix ENS 10.x STIG:
ENS-FW-000008
(in versions v2 r14 through v2 r13)
Title
(CUI) The ENS Firewall rules must use Trellix GTI Network Reputation. (Cat II impact)
Discussion
(CUI) Global Threat Intelligence (GTI) is a collective intelligence from sensors and cross-vector intelligence from web, email, and network threats to compile scores that reflect the likelihood of whether a file in question is malware. The collective intelligence is constantly being updated, more frequently than the typical daily antivirus signature files. With File Reputation lookup, a more real-time response to potential malicious code is realized than with the local-running antivirus software, since by querying the cloud-based database when a file appears to be suspicious, up-to-the-minute intelligence is provided. This type of protection reduces the threat protection time period from days to milliseconds, increases malware detection rates, and reduces downtime and remediation costs associated with malware attacks. Using File Reputation lookup is mandated by US CYBERCOM on DoD systems.
Check Content
(CUI) Note: This requirement is Not Applicable for disconnected or classified networks. Access the ePO server console. Select Menu >> Policy >> Policy Catalog and then select “Endpoint Security Firewall” from the Product list. From the Category list, select “Options”. Select each configured Options policy. Verify the Trellix GTI Network Reputation: Check “Treat Trellix GTI match as intrusion” is selected with “Log matching traffic” and “Block all untrusted executables” not selected. If the Trellix GTI Network Reputation: Check “Treat Trellix GTI match as intrusion” is not selected, this is a finding.
Fix Text
(CUI) Access the ePO server console. Select Menu >> Policy >> Policy Catalog and then select "Endpoint Security Firewall" from the Product list. From the Category list, select "Options". Select each configured Options policy. Select the Trellix GTI Network Reputation: Check "Treat Trellix GTI match as intrusion" option. Uncheck Log matching traffic. Uncheck Block all untrusted executables. Click "Save".
Additional Identifiers
Rule ID: SV-230202r944456_rule
Vulnerability ID: V-230202
Group Title: SRG-APP-000272
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001247 |
The information system automatically updates malicious code protection mechanisms. |
Controls
Number | Title |
---|---|
SI-3 (2) |
Automatic Updates |