STIGQter STIGQter: STIG Summary: Symantec Edge SWG ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Nov 2025:

The Edge SWG must control remote access methods.

DISA Rule

SV-279203r1170670_rule

Vulnerability Number

V-279203

Group Title

SRG-NET-000313-ALG-000010

Rule Version

SYME-00-007500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. In the Edge SWG Web UI, navigate to the Administration tab.
2. Click "Data and Cloud Services", then "Content Filtering".
3. Enable BlueCoat Content Filtering.
4. Click "BlueCoat" and check the box for "Always" under "Lookup Mode".
5. Test the download. If the URL cannot be reached, troubleshoot before proceeding to determine if there are networking, reachability, or routing issues.

1. In the Edge SWG Web UI, navigate to the VPM.
2. Go to the Web Access Layer.
3. Create a URL filter list rule if one has not been created, click "Add Rule".
4. For source use "Any".
5. Under "Destination", left-click and then click "Set".
6. Click "Add new Object and Request URL Category".
7. Enter a name and click the "BlueCoat" area.
8. Click each category that users will be blocked from accessing, then click "Apply and Set".
9. Under Service, click the "All HTTP" client protocol.
10. Click "Set".
11. Under "Action", click the "DOD-BLOCK" exception page previously created.
12. Under "Track", click the EventLog tracking previously created.
13. Repeat these steps for all other client protocol services for which forward proxying for users will be completed.
14. Click "Apply Policy".

Check Contents

1. In the Edge SWG Web UI, navigate to the Administration tab.
2. Click "Data and Cloud Services", then "Content Filtering".
3. If BlueCoat Content Filtering is disabled, this is a finding.
4. Click "BlueCoat".

If the Lookup Mode is not set to "Always", this is a finding.

1. In the Edge SWG Web UI, navigate to the VPM.
2. Go to the Web Access Layer.

If there are no URL filtering rules created, this is a finding.

If there is a URL filtering list and no categories are selected, this is a finding.

Vulnerability Number

V-279203

Documentable

False

Rule Version

SYME-00-007500

Severity Override Guidance

1. In the Edge SWG Web UI, navigate to the Administration tab.
2. Click "Data and Cloud Services", then "Content Filtering".
3. If BlueCoat Content Filtering is disabled, this is a finding.
4. Click "BlueCoat".

If the Lookup Mode is not set to "Always", this is a finding.

1. In the Edge SWG Web UI, navigate to the VPM.
2. Go to the Web Access Layer.

If there are no URL filtering rules created, this is a finding.

If there is a URL filtering list and no categories are selected, this is a finding.

Check Content Reference

M

Target Key

5725