Check: TIDX-SV-000004
Trellix TIE/DXL STIG:
TIDX-SV-000004
(in version v2 r2)
Title
The McAfee Threat Intelligence Exchange (TIE) Server Management Global Threat Intelligence (GTI) Reputations must be enabled to get file reputation from the McAfee GTI. (Cat I impact)
Discussion
This setting dictates whether to use the McAfee GTI to get file reputation. McAfee GTI is used if the TIE server does not have reputation information for a file or if the TIE server is unavailable.
Check Content
This check needs to be completed for the active McAfee TIE Server Management policy that manages the site McAfee TIE. For TIE servers on the SIPRNet or classified network, GTI must be disabled; therefore this requirement is Not Applicable. From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the McAfee TIE Server Management from Products. Under "Actions", select Edit for the policy that manages the site McAfee TIE. Select the "McAfee Global Threat Intelligence" tab. For "GTI Reputation", verify the check box for "Enabled" is selected. If the check box for "Enabled" is not selected, this is a finding.
Fix Text
From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the McAfee TIE Server Management from Products. Under "Actions", select Edit for the policy that manages the site McAfee TIE. Select the "McAfee Global Threat Intelligence" tab. For "GTI Reputation", select the check box for "Enabled". Click Save.
Additional Identifiers
Rule ID: SV-222000r559662_rule
Vulnerability ID: V-222000
Group Title: SRG-APP-000278
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001242 |
The organization configures malicious code protection mechanisms to perform real-time scans of files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy. |
Controls
Number | Title |
---|---|
SI-3 |
Malicious Code Protection |