CylanceON-PREM must be configured to support integration with a third-party Security Information and Event Management (SIEM) to support notifications.
DISA Rule
SV-272632r1113445_rule
Vulnerability Number
V-272632
Group Title
SRG-APP-000108
Rule Version
CYLN-OP-000180
Severity
CAT II
CCI(s)
- CCI-000139 - Alert organization-defined personnel or roles within an organization-defined time period in the event of an audit logging process failure.
- CCI-000158 - Provide the capability to process, sort, and search audit records for events of interest based on organization-defined audit fields within audit records.
- CCI-001348 - Store audit records on an organization-defined frequency in a repository that is part of a physically different system or system component that the system or component being audited.
- CCI-001350 - Implement cryptographic mechanisms to protect the integrity of audit information.
- CCI-001876 - Provide an audit reduction capability that supports on-demand reporting requirements.
- CCI-001851 - Transfer audit logs per organization-defined frequency to a different system, system component, or media than the system or system component conducting the logging.
- CCI-001858 - Provide an alert in an organization-defined real-time-period to organization-defined personnel, roles, and/or locations when organization-defined audit failure events requiring real-time alerts occur.
- CCI-002702 - Shut the system down, restart the system, and/or initiate organization-defined alternative action(s) when anomalies in the operation of the organization-defined security functions are discovered.
- CCI-003821 - Implement the capability to centrally review and analyze audit records from multiple components within the system.
- CCI-003831 - Alert organization-defined personnel or roles upon detection of unauthorized access, modification, or deletion of audit information.
Weight
10
Fix Recommendation
Configure SIEM. Administrator privileges are required.
1. Log in to the admin console.
2. Navigate to CONFIGURATION >> Settings.
3. Find Syslog/SIEM.
4. Click on the edit button beside Syslog/SIEM.
5. Slide the button to enable.
6. Populate the Syslog/SIEM configuration.
7. Click the green check to save.
Check Contents
Verify SIEM, Administrator privileges are required.
1. Log in to the admin console.
2. Navigate to CONFIGURATION >> Settings.
3. Find Syslog/SIEM.
If Syslog/SIEM is not enabled or the settings are not configured correctly, this is a finding.
Vulnerability Number
V-272632
Documentable
False
Rule Version
CYLN-OP-000180
Severity Override Guidance
Verify SIEM, Administrator privileges are required.
1. Log in to the admin console.
2. Navigate to CONFIGURATION >> Settings.
3. Find Syslog/SIEM.
If Syslog/SIEM is not enabled or the settings are not configured correctly, this is a finding.
Check Content Reference
M
Target Key
5692