STIGQter STIGQter: STIG Summary: Symantec ProxySG NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2020:

Symantec ProxySG must be configured to enforce user authorization to implement least privilege.

DISA Rule

SV-104485r1_rule

Vulnerability Number

V-94655

Group Title

SRG-APP-000033-NDM-000212

Rule Version

SYMP-NM-000020

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Obtain a list of authorized personnel or host IP addresses and associated roles/privileges. Remove any unauthorized users or excess privileges.

1. Log on to the Web Management Console.
2. Click Configuration >> Policy >> Visual Policy Manager.
3. Click the "Launch" button.
4. Click the "Admin Access" layer.
5. Delete unauthorized users or host IP addresses and adjust or correct user authorizations for "allow read-only" or "allow read-write".

Check Contents

Obtain a list of authorized personnel or host IP addresses and associated roles/privileges. Verify there are no unauthorized users/host IP addresses. Verify there are no users or host IP addresses with excess privileges.

1. Log on to the Web Management Console.
2. Click Configuration >> Policy >> Visual Policy Manager.
3. Click the "Launch" button.
4. Click the "Admin Access" layer.

Verify that any users, hosts, and groups listed in the "source" field of each rule that have an action of "Allow" are authorized administrators with read-write, read-only, or deny.

If users or hosts are configured for excess privileges, this is a finding.

Vulnerability Number

V-94655

Documentable

False

Rule Version

SYMP-NM-000020

Severity Override Guidance

Obtain a list of authorized personnel or host IP addresses and associated roles/privileges. Verify there are no unauthorized users/host IP addresses. Verify there are no users or host IP addresses with excess privileges.

1. Log on to the Web Management Console.
2. Click Configuration >> Policy >> Visual Policy Manager.
3. Click the "Launch" button.
4. Click the "Admin Access" layer.

Verify that any users, hosts, and groups listed in the "source" field of each rule that have an action of "Allow" are authorized administrators with read-write, read-only, or deny.

If users or hosts are configured for excess privileges, this is a finding.

Check Content Reference

M

Target Key

3517

Comments