STIGQter STIGQter: STIG Summary: McAfee Application Control 8.x Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Oct 2020:

The Solidcore client must be enabled.

DISA Rule

SV-213326r506897_rule

Vulnerability Number

V-213326

Group Title

SRG-APP-000386

Rule Version

MCAC-TE-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Although there is more than one way to deploy and enable the Solidcore client, the following is the method described in the McAfee Application Control Installation Guide.

From the ePO server console System Tree, select "My Organization" in the System Tree.

To deploy the Solidcore 8.x client:

Select "This Group and All Subgroups".
Select the asset and view its properties.
Click on the "Actions" button at the bottom of the screen.
Select "Agent".
Select "Modify Tasks on a Single System".
Click "Actions".
Select "New Client Task Assignment" to open the "Client Task Assignment Builder" page.
Specify the task name and add descriptive information.
Select the target platform, subplatform, and version.
Select the "Solidcore 8.0.0" product from the "Products and components" list.
Select the "Install" action.
Select the language of the package.
Specify the branch where to add the package.
Click "Save", then click "Next to open the "Schedule" page.
Specify scheduling details, then click "Next".
Review details, then click "Save".

To enable the Solidcore 8.x client and scan for inventory:

Select "This Group and All Subgroups".
Select the asset and view its properties.
Click on the "Actions" button at the bottom of the screen.
Select "Agent".
Select "Modify Tasks on a Single System".
Click "Actions".
Select "New Client Task Assignment" to open the "Client Task Assignment Builder" page.
Select the "Solidcore 8.0.0" product and "SC: Enable" task type, then click "Create New Task".

Check Contents

From the ePO server console System Tree, select the "Systems" tab.

Select "This Group and All Subgroups".

Select the asset(s) that need the organization-specific policy and view its properties.

Click on the "Products" tab.

Under "Product", verify the Solidcore 8.x client is listed as a product. If exists, click on the row to review additional information. Verify status shows "Enabled".

If the Solidcore 8.x client is listed as an installed product but the status is not "Enabled", this is a finding.

Vulnerability Number

V-213326

Documentable

False

Rule Version

MCAC-TE-000100

Severity Override Guidance

From the ePO server console System Tree, select the "Systems" tab.

Select "This Group and All Subgroups".

Select the asset(s) that need the organization-specific policy and view its properties.

Click on the "Products" tab.

Under "Product", verify the Solidcore 8.x client is listed as a product. If exists, click on the row to review additional information. Verify status shows "Enabled".

If the Solidcore 8.x client is listed as an installed product but the status is not "Enabled", this is a finding.

Check Content Reference

M

Target Key

3982

Comments