Check: TIDX-SV-000003
Trellix TIE/DXL STIG:
TIDX-SV-000003
(in version v2 r2)
Title
The McAfee Threat Intelligence Exchange (TIE) Server Management Product Improvement Program must be disabled from collecting and sending anonymous data about certificates and file hashes to McAfee. (Cat II impact)
Discussion
The Product Improvement Program allows McAfee to collect anonymous data about certificates and file hashes. This data helps McAfee learn about threats and prioritize what is allowed or blocked.
Check Content
This check needs to be completed for the active McAfee TIE Server Management policy that manages the site McAfee TIE. From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the McAfee TIE Server Management from Products. Under "Actions", select Edit for the policy that manages the site McAfee TIE. Select the "General" tab. Under "Product Improvement Program", verify the check box for "Enabled" is not selected. If the check box for "Enabled" is selected, this is a finding.
Fix Text
From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the McAfee TIE Server Management from Products. Under "Actions", select Edit for the policy that manages the site McAfee TIE. Select the "General" tab. Under "Product Improvement Program", remove the check from the check box for "Enabled". Click Save.
Additional Identifiers
Rule ID: SV-221999r506938_rule
Vulnerability ID: V-221999
Group Title: SRG-APP-000427
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002470 |
Only allow the use of organization-defined certificate authorities for verification of the establishment of protected sessions. |
Controls
Number | Title |
---|---|
SC-23(5) |
Allowed Certificate Authorities |