Check: ENS-TP-000209
Trellix ENS 10.x STIG:
ENS-TP-000209
(in versions v2 r14 through v2 r13)
Title
(U) The Trellix ENS Threat Prevention On-Access Scan Global Threat Intelligence (GTI) sensitivity level must be configured to medium or higher. (Cat II impact)
Discussion
(U) Antivirus software vendors use collective intelligence from sensors and cross-vector intelligence from web, email, and network threats to compile scores that reflect the likelihood of whether a file in question is malware. The collective intelligence is constantly being updated -- more frequently than the typical daily antivirus signature files. With File Reputation lookup, a more real-time response to potential malicious code is realized than with the local-running antivirus software since by querying the cloud-based database when a file appears to be suspicious, up-to-the-minute intelligence is provided. This type of protection reduces the threat protection time period from days to milliseconds, increases malware detection rates, and reduces downtime and remediation costs associated with malware attacks. Using File Reputation lookup is mandated by USCYBERCOM on DoD systems.
Check Content
(U) NOTE: This requirement is Not Applicable on Classified/SIPRNet or otherwise closed networks. Access the ePO server console. Select Menu >> Policy >> Policy Catalog From the "Product" list, select "Endpoint Security Threat Prevention". From the "Category" list, select "On-Access Scan". Select each configured On-Access Scan policy. Verify On-Access Scan >> Trellix GTI >> "Enable Trellix GTI" is selected and the "Sensitivity level" is configured to "medium" or higher. If On-Access Scan >> Trellix GTI >> "Enable Trellix GTI" is not selected with a "Sensitivity level" of "medium" or higher, this is a finding.
Fix Text
(U) Access the ePO server console. Select Menu >> Policy >> Policy Catalog From the "Product" list, select "Endpoint Security Threat Prevention". From the "Category" list, select "On-Access Scan". Select each configured On-Access Scan policy. Select the On-Access Scan >> Trellix GTI >> "Enable Trellix GTI" option. Select "Sensitivity level" of "medium" or higher. Click "Save".
Additional Identifiers
Rule ID: SV-228243r944470_rule
Vulnerability ID: V-228243
Group Title: SRG-APP-000278
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001242 |
The organization configures malicious code protection mechanisms to perform real-time scans of files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy. |
Controls
Number | Title |
---|---|
SI-3 |
Malicious Code Protection |