Check: TIDX-SV-000001
Trellix TIE/DXL STIG:
TIDX-SV-000001
(in version v2 r2)
Title
The McAfee Threat Intelligence Exchange (TIE) server and its installed components must be at the latest vendor released version. (Cat I impact)
Discussion
This requirement will apply to software applications that are not part of that patch management solution. Time frames for application of security-relevant software updates may be dependent upon the Information Assurance Vulnerability Management (IAVM) process. There must be processes in place to ensure application has all security-relevant software updates within an identified time period from the availability of the update. The specific time period will be defined by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs). Since the McAfee TIE/DXL system will be under the DISA HBSS Program Office configuration management process, all updates must be tested with the HBSS baseline prior to being released for production systems. Due to the manual nature of these updates, the severity of this requirement is a CAT I.
Check Content
From the ePO server console, select the System Tree tab. Under System Tree, navigate to find the McAfee TIE server asset and double-click to open its properties. Review the list of Installed Products. Verify the versions of McAfee DXL Management, McAfee DXL Client, and McAfee Threat Intelligence Exchange Server are all at the latest vendor released and Program Office approved levels. If any of the installed products are not at the most current vendor-released and Program-office-approved level, this is a finding.
Fix Text
Install all patches and updates approved by the program office.
Additional Identifiers
Rule ID: SV-221997r558648_rule
Vulnerability ID: V-221997
Group Title: SRG-APP-000456
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002605 |
Install security-relevant software updates within an organization-defined time period of the release of the updates. |
Controls
Number | Title |
---|---|
SI-2 |
Flaw Remediation |