The TPS must generate a log record so an alert can be configured to, at a minimum, the system administrator when malicious code is detected.
DISA Rule
SV-242199r1018785_rule
Vulnerability Number
V-242199
Group Title
SRG-NET-000248-IDPS-00206
Rule Version
TIPP-IP-000360
Severity
CAT I
CCI(s)
- CCI-002624 - Configure malicious code protection mechanisms to perform real-time scans of files from external sources at endpoint; and/or network entry and exit points as the files are downloaded, opened, or executed in accordance with organizational policy.
- CCI-001243 - Configure malicious code protection mechanisms to block malicious code; quarantine malicious code; and/or take organization-defined action(s) in response to malicious code detection.
- CCI-002684 - Audit and/or alert organization-defined personnel when unauthorized network services are detected.
Weight
10
Fix Recommendation
1. In the Trend Micro SMS, navigate to "Profiles" and "Shared Settings".
2. Under "Action Sets:
a. Select "Block+Notify" and edit.
b. Select Notifications, and check "Remote Syslog".
c. Select "Finish".
Check Contents
1. In the Trend Micro SMS, navigate to "Profiles" and "Shared Settings".
2. Under "Action Sets, if "Remote Syslog", are not enabled for both the "Block+Notify" and "Block+Notify+Trace", this is a finding.
Vulnerability Number
V-242199
Documentable
False
Rule Version
TIPP-IP-000360
Severity Override Guidance
1. In the Trend Micro SMS, navigate to "Profiles" and "Shared Settings".
2. Under "Action Sets, if "Remote Syslog", are not enabled for both the "Block+Notify" and "Block+Notify+Trace", this is a finding.
Check Content Reference
M
Target Key
5367