STIGQter STIGQter: STIG Summary: Trend Micro TippingPoint IDPS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 24 Oct 2024:

The SMS and TPS must provide log information in a format that can be extracted and used by centralized analysis tools.

DISA Rule

SV-242187r710104_rule

Vulnerability Number

V-242187

Group Title

SRG-NET-000091-IDPS-00193

Rule Version

TIPP-IP-000210

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties".
2. Select the "syslog" tab.
3. Click "New".
4. Under syslog server type the hostname or IP address of the syslog server.
5. Click TCP to ensure logging data is queued in the case of disconnection of the syslog server.
6. Type the port used by the centralized logging server (traditionally it is port 514).
7. Under log type, select "Device System".
8. Under facility click "Log System".
9. Click Event timestamp under "Include Timestamp in Header".
10. Select "Include SMS hostname in header".
Repeat this one more time changing the Log Type to include SMS System.

Check Contents

1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties".
2. Select the "syslog" tab. If a syslog server is not configured to send the following audit logs, this is a finding:
- Device System
- SMS system

Vulnerability Number

V-242187

Documentable

False

Rule Version

TIPP-IP-000210

Severity Override Guidance

1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties".
2. Select the "syslog" tab. If a syslog server is not configured to send the following audit logs, this is a finding:
- Device System
- SMS system

Check Content Reference

M

Target Key

5367