Check: TIDX-SV-000017
Trellix TIE/DXL STIG:
TIDX-SV-000017
(in versions v2 r2 through v1 r0.1)
Title
The McAfee Threat Intelligence Exchange (TIE) Server Management Performance metrics report must be enabled. (Cat II impact)
Discussion
The McAfee TIE metrics collected include resource usage and capacity, which measures CPU, RAM, disk, and network usage when using the TIE solution over a few hours, latency impact and scalability, which measures the throughput capacity differences when adding new secondary server instances, and caching benefits on required bandwidth and throughput and increased service throughput when implementing cached reputation stores. An organization will determine the best frequency to ensure continued performance metric monitoring for the size of their network but must not be configured for more than 30 minutes.
Check Content
This check needs to be completed for the active McAfee TIE Server Management policy that manages the site McAfee TIE. From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the McAfee TIE Server Management from Products. Under "Actions", select Edit for the policy that manages the site McAfee TIE. Select the "Server Configuration" tab. Under "Performance metrics report", verify the check box for "Enabled" is selected. If the "Performance metrics report" check box for "Enabled" is not selected, this is a finding.
Fix Text
From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the McAfee TIE Server Management from Products. Select the "Server Configuration" tab. Under "Performance metrics report", select the check box for "Enabled".
Additional Identifiers
Rule ID: SV-222013r506938_rule
Vulnerability ID: V-222013
Group Title: SRG-APP-000111
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000154 |
Provide the capability to centrally review and analyze audit records from multiple components within the system. |
Controls
Number | Title |
---|---|
AU-6(4) |
Central Review and Analysis |