Check: TIDX-SV-000017
Trellix TIE/DXL STIG:
TIDX-SV-000017
(in versions v3 r1 through v2 r3)
Title
The Trellix Threat Intelligence Exchange (TIE) Server Management Performance metrics report must be enabled. (Cat II impact)
Discussion
The Trellix TIE metrics collected include resource usage and capacity, which measures CPU, RAM, disk, and network usage when using the TIE solution over a few hours, latency impact and scalability, which measures the throughput capacity differences when adding new secondary server instances, and caching benefits on required bandwidth and throughput and increased service throughput when implementing cached reputation stores. An organization will determine the best frequency to ensure continued performance metric monitoring for the size of their network but must not be configured for more than 30 minutes.
Check Content
This check must be completed for the active Trellix TIE Server Management policy that manages the site Trellix TIE. From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the Trellix TIE Server Management from Products. Under "Actions", select Edit for the policy that manages the site Trellix TIE. Select the "Server Configuration" tab. Under "Performance metrics report", verify the check box for "Enabled" is selected. If the "Performance metrics report" check box for "Enabled" is not selected, this is a finding.
Fix Text
From the ePO server console, select the Policy Catalog tab. From the Policy Catalog, select the Trellix TIE Server Management from Products. Select the "Server Configuration" tab. Under "Performance metrics report", select the check box for "Enabled".
Additional Identifiers
Rule ID: SV-222013r960918_rule
Vulnerability ID: V-222013
Group Title: SRG-APP-000111
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000154 |
Provide the capability to centrally review and analyze audit records from multiple components within the system. |
Controls
Number | Title |
---|---|
AU-6(4) |
Central Review and Analysis |