STIGQter STIGQter: STIG Summary: Trend Micro TippingPoint IDPS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The TPS must provide audit record generation capability for detection events based on implementation of policy filters, rules, signatures, and anomaly analysis.

DISA Rule

SV-242176r1028382_rule

Vulnerability Number

V-242176

Group Title

SRG-NET-000113-IDPS-00013

Rule Version

TIPP-IP-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the Trend Micro SMS interface
1. Go to the "Admin" tab and select "Server Properties".
2. Select the "syslog" tab.
3. Click "New".
4. Under syslog server, type the hostname or IP address of the syslog server. (If using Encrypted TCP, and depending on the syslog server, enter the hostname, if needed).
5. Click "TCP" to ensure logging data is queued in the case of disconnection of the syslog server.
6. Type the port used by the centralized logging server (traditionally it is port 514 for TCP and 6514 for Encrypted TCP).
7. Under log type, select "Device Audit".
8. Repeat steps to configure all syslog servers.
9. Under facility click "Log Audit".
10. Click Event timestamp under "Include Timestamp in Header".
11. Select "include SMS hostname in header".

Repeat this three more times to change the Log Type to include Device System, SMS Audit, and SMS System.

Check Contents

In the Trend Micro SMS interface:
1. Go to the "Admin" tab and select "Server Properties".
2. Select the "Syslog" tab.
3. Navigate to Device Audit >> Device System >> SMS Audit >> SMS system.
4. Review the settings for all syslogs servers.

If each syslog server is not configured to use TCP or Encrypted TCP, this is a finding.

Vulnerability Number

V-242176

Documentable

False

Rule Version

TIPP-IP-000100

Severity Override Guidance

In the Trend Micro SMS interface:
1. Go to the "Admin" tab and select "Server Properties".
2. Select the "Syslog" tab.
3. Navigate to Device Audit >> Device System >> SMS Audit >> SMS system.
4. Review the settings for all syslogs servers.

If each syslog server is not configured to use TCP or Encrypted TCP, this is a finding.

Check Content Reference

M

Target Key

5367