STIGQter STIGQter: STIG Summary: AvePoint Compliance Guardian Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 15 Mar 2023:

Compliance Guardian must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.

DISA Rule

SV-256843r890139_rule

Vulnerability Number

V-256843

Group Title

SRG-APP-000142

Rule Version

APCG-00-000020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Compliance Guardian Manager communication port setting.
- On the Compliance Guardian Manager server, open the "Compliance Guardian Manager Configuration Tool" from the Start Menu.
- Click "Control Service Configuration" on the left.
- Change the Website Port.
- Click "OK" to save settings.

Configure the Compliance Guardian Agent communication port setting.
- On the Compliance Guardian Agent server, open "Compliance Guardian Agent Configuration Tool".
- Navigate to the "Host And Port" panel.
- Change the Agent Port.
- Click "OK" to save settings.

Configure the Compliance Guardian Control Service update port setting.
- Log on to Compliance Guardian with admin account.
- On the Control Panel page in the License and Update section, click "Update Manager", then click "Settings".
- Change the "Specify a port number" to install the update.
- Click "Save" to save settings.

Check Contents

Check the Compliance Guardian Manager communication port setting.
- On the Compliance Guardian Manager server, open "Compliance Guardian Manager Configuration Tool" from the Start Menu.
- Click "Control Service Configuration" on the left.
- Verify the Website Port.

If any ports used by the Compliance Guardian Manager Services are not in accordance with the PPSM CAL or are not AO approved, this is a finding.

Check the Compliance Guardian Agent communication port setting.
- On the Compliance Guardian Agent server, open "Compliance Guardian Agent Configuration Tool".
- Navigate to the "Host And Port" panel.
- Verify the Agent Port.

If the Agent Port is are not in accordance with the PPSM CAL or are not AO approved, this is a finding.

Check the Compliance Guardian Control Service update port setting.
- Log on to Compliance Guardian with admin account.
- On the Control Panel page in the License and Update section, click "Update Manager", then click "Settings".
- Verify the "Specify a port number" to install the update.

If the Update Port is not in accordance with the PPSM CAL or is not AO approved, this is a finding.

Vulnerability Number

V-256843

Documentable

False

Rule Version

APCG-00-000020

Severity Override Guidance

Check the Compliance Guardian Manager communication port setting.
- On the Compliance Guardian Manager server, open "Compliance Guardian Manager Configuration Tool" from the Start Menu.
- Click "Control Service Configuration" on the left.
- Verify the Website Port.

If any ports used by the Compliance Guardian Manager Services are not in accordance with the PPSM CAL or are not AO approved, this is a finding.

Check the Compliance Guardian Agent communication port setting.
- On the Compliance Guardian Agent server, open "Compliance Guardian Agent Configuration Tool".
- Navigate to the "Host And Port" panel.
- Verify the Agent Port.

If the Agent Port is are not in accordance with the PPSM CAL or are not AO approved, this is a finding.

Check the Compliance Guardian Control Service update port setting.
- Log on to Compliance Guardian with admin account.
- On the Control Panel page in the License and Update section, click "Update Manager", then click "Settings".
- Verify the "Specify a port number" to install the update.

If the Update Port is not in accordance with the PPSM CAL or is not AO approved, this is a finding.

Check Content Reference

M

Target Key

5531