SV-272882r1119408_rule
V-272882
SRG-APP-000207
MSDE-00-000100
CAT II
10
Access the MDE portal as a user with at least a Security Administrator or equivalent role:
1. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Alerts.
2. Click "+Add notification rule".
3. Enter Name, Notification settings, and Recipients as defined by the AO.
4. Click "Save". Repeat as necessary.
5. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Vulnerabilities.
6. Click "+Add notification rule".
7. Enter Name, Notification settings, and Recipients as defined by the AO.
8. Click "Save". Repeat as necessary.
Access the MDE portal as a user with at least a Security Administrator or equivalent role:
1. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Alerts.
2. For each defined Notification rule:
- Click on the rule and select "Edit" to enter the "Update notification rule" screen.
- Verify the notification settings are configured as defined by the authorizing official (AO).
- Verify the Recipient Emails are assigned as defined by the AO.
3. Click "Cancel".
4. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Vulnerabilities.
5. For each defined notification rule:
- Click on the rule and select "Edit" to enter the "Update notification rule" screen.
- Verify the notification settings are configured as defined by the AO.
- Verify the Recipient Emails are assigned as defined by the AO.
6. Click "Cancel".
If Settings >> Endpoints >> Email notifications (under Permissions) >> Alerts does not display rules as defined by the AO, this is a finding.
If Settings >> Endpoints >> Email notifications (under Permissions) >> Vulnerabilities does not display rules as defined by the AO, this is a finding.
When selecting each rule individually, if the Notification Settings and Recipient Emails are not as defined by the AO, this is a finding.
V-272882
False
MSDE-00-000100
Access the MDE portal as a user with at least a Security Administrator or equivalent role:
1. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Alerts.
2. For each defined Notification rule:
- Click on the rule and select "Edit" to enter the "Update notification rule" screen.
- Verify the notification settings are configured as defined by the authorizing official (AO).
- Verify the Recipient Emails are assigned as defined by the AO.
3. Click "Cancel".
4. In the navigation pane, select Settings >> Endpoints >> Email notifications (under General) >> Vulnerabilities.
5. For each defined notification rule:
- Click on the rule and select "Edit" to enter the "Update notification rule" screen.
- Verify the notification settings are configured as defined by the AO.
- Verify the Recipient Emails are assigned as defined by the AO.
6. Click "Cancel".
If Settings >> Endpoints >> Email notifications (under Permissions) >> Alerts does not display rules as defined by the AO, this is a finding.
If Settings >> Endpoints >> Email notifications (under Permissions) >> Vulnerabilities does not display rules as defined by the AO, this is a finding.
When selecting each rule individually, if the Notification Settings and Recipient Emails are not as defined by the AO, this is a finding.
M
5693