Check: TIDX-BK-000002
Trellix TIE/DXL STIG:
TIDX-BK-000002
(in versions v3 r1 through v2 r3)
Title
The Trellix Data Exchange Layer (DXL) Broker Management Client Connection Limit must be configured to 50,000 users or less. (Cat II impact)
Discussion
Application management includes the ability to control the number of users and user sessions that utilize an application. Limiting the number of allowed users and sessions per user is helpful in limiting risks related to denial-of-service (DoS) attacks. This requirement may be met via the application or by utilizing information system session control provided by a web server with specialized session management capabilities. If it has been specified that this requirement will be handled by the application, the capability to limit the maximum number of concurrent single user sessions must be designed and built into the application. This requirement addresses concurrent sessions for information system accounts and does not address concurrent sessions by single users via multiple system accounts. The maximum number of concurrent sessions should be defined based upon mission needs and the operational environment for each system. The Trellix DXL Client Connection Limit sets the number of clients that can be connected to broker that uses the policy. The default is 50,000.
Check Content
This check must be completed for the active Trellix TIE Server Management policy that manages the site Trellix TIE. From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the Trellix DXL Broker Management from Products. Under "Actions", select Edit for the policy that manages the site Trellix TIE. Verify the Client Connection Limit is set to 50,000 or less. If the Client Connection Limit is not set to 50,000 or less, this is a finding.
Fix Text
From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the Trellix DXL Broker Management from Products. Under "Actions", select Edit for the policy that manages the site Trellix TIE. Set the Client Connection Limit to 50,000 or less.
Additional Identifiers
Rule ID: SV-221990r960735_rule
Vulnerability ID: V-221990
Group Title: SRG-APP-000001
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000054 |
Limit the number of concurrent sessions for each organization-defined account and/or account type to an organization-defined number. |
Controls
Number | Title |
---|---|
AC-10 |
Concurrent Session Control |