STIGQter STIGQter: STIG Summary: Trend Micro TippingPoint NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Apr 2025:

The TippingPoint SMS must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.

DISA Rule

SV-242236r1082950_rule

Vulnerability Number

V-242236

Group Title

SRG-APP-000142-NDM-000245

Rule Version

TIPP-NM-000200

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

1. For SMS, click "Admin and Management".
2. Uncheck "HTTPS", and "TAXII". Ensure only SSH and Ping are checked.
3. Click edit on FIPS Mode.
4. Under an approved change window only, enable FIPS Crypto Core. This will cause a reboot; only do this when authorized.
5. For TPS, click Devices >> All Devices, and the subject device hostname.
6. Click "Device Configuration" and select "Services".
7. Uncheck "HTTPS", and "TAXII". Ensure only SSH and Ping are checked.
Note: FIPS mode is enabled in TIPP-NM-000200.

Check Contents

1. For SMS, click "Admin and Management".
2. Ensure only Ping is enabled and the SMS is in FIPS Mode.
3. For TPS, click Devices >> All Devices, and the subject device hostname.
4. Click "Device Configuration" and select "Services". Ensure only TLS 1.2 is enabled.
5. Verify only SSH and Ping are enabled and the SMS is in FIPS Mode.

If any other services are enabled, this is a finding.

Vulnerability Number

V-242236

Documentable

False

Rule Version

TIPP-NM-000200

Severity Override Guidance

1. For SMS, click "Admin and Management".
2. Ensure only Ping is enabled and the SMS is in FIPS Mode.
3. For TPS, click Devices >> All Devices, and the subject device hostname.
4. Click "Device Configuration" and select "Services". Ensure only TLS 1.2 is enabled.
5. Verify only SSH and Ping are enabled and the SMS is in FIPS Mode.

If any other services are enabled, this is a finding.

Check Content Reference

M

Target Key

5369