STIGQter STIGQter: STIG Summary: Trend Micro Deep Security 9.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Feb 2016:

Trend Deep Security must prohibit user installation of software without explicit privileged status.

DISA Rule

SV-80467r1_rule

Vulnerability Number

V-65977

Group Title

SRG-APP-000378

Rule Version

TMDS-00-000285

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Trend Deep Security server to prohibit user installation of software without explicit privileged status.

Configure the application to prevent non-authorized users from updating Deep Security by selecting Administration >> User Management >> Roles.
Right-Click >> Properties on any of the roles listed and choose “Other Rights.”
Set the “Updates” setting to “View Only” or “Hide”.

Check Contents

Review the Trend Deep Security server configuration to ensure user installation of software without explicit privileged status is prohibited.

Analyze the system using Administration >> User Management >> Roles.
Review each role created that is not “Full Access”.
Right-Click >> Properties on the desired role, and select “Other Rights.”
The “Updates” setting should be set to “View Only” or “Hide.”

If any other option is selected other than “View Only” or “Hide”, this is a finding.

Vulnerability Number

V-65977

Documentable

False

Rule Version

TMDS-00-000285

Severity Override Guidance

Review the Trend Deep Security server configuration to ensure user installation of software without explicit privileged status is prohibited.

Analyze the system using Administration >> User Management >> Roles.
Review each role created that is not “Full Access”.
Right-Click >> Properties on the desired role, and select “Other Rights.”
The “Updates” setting should be set to “View Only” or “Hide.”

If any other option is selected other than “View Only” or “Hide”, this is a finding.

Check Content Reference

M

Target Key

2955

Comments