STIGQter STIGQter: STIG Summary: Bromium Secure Platform 4.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 May 2018:

The Bromium Enterprise Controller (BEC) must be configured to immediately disconnect or disable remote access to the BEC.

DISA Rule

SV-95145r1_rule

Vulnerability Number

V-80441

Group Title

SRG-APP-000316

Rule Version

BROM-00-000685

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable access for the user account by assigning a role with zero privileges enabled. A role that has zero privileges assigned to it must exist, along with a group that is assigned to the role.

1. From the management console, click on the arrow next to "Settings".
2. Click on "Users".
3. Select the user that has been identified for disabling.
4. Add the user to the group that is associated with the role that carries zero privileges.
5. Delete/remove all other groups for that user.
6. Click "Save".

Check Contents

Inspect the BEC user settings for a role with no privileges and a group that is tied to that role. 

1. From the management console, click on the arrow next to "Settings".
2. Click on "Roles".
3. Identify and select the role that has no privileges assigned to it.
4. Inspect the "Role" settings to ensure that a group has been assigned.

If the BEC is not configured to immediately disconnect or disable remote access to the information system, this is a finding.

Vulnerability Number

V-80441

Documentable

False

Rule Version

BROM-00-000685

Severity Override Guidance

Inspect the BEC user settings for a role with no privileges and a group that is tied to that role. 

1. From the management console, click on the arrow next to "Settings".
2. Click on "Roles".
3. Identify and select the role that has no privileges assigned to it.
4. Inspect the "Role" settings to ensure that a group has been assigned.

If the BEC is not configured to immediately disconnect or disable remote access to the information system, this is a finding.

Check Content Reference

M

Target Key

3375

Comments