STIGQter STIGQter: STIG Summary: Bromium Secure Platform 4.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 May 2018:

The Bromium monitoring module installed on the Bromium Enterprise Controller (BEC) or Bromium vSentry must generate an event and forward to the central log server when anomalies in the operation of security functions of the BEC or Bromium vSentry application are discovered.

DISA Rule

SV-95175r1_rule

Vulnerability Number

V-80471

Group Title

SRG-APP-000474

Rule Version

BROM-00-001155

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

The BEC administrator must work with the site administrator to forward contents of "worker.log" and "default.log" to a central log server in real time.

1. Automatically forward all contents of "worker.log" and "default.log" to the site's centralized log server in real time. 
2. Install the file monitoring agent that is provided by the site's central log server (e.g., syslog, SIEM) and configure to monitor and forward "worker.log" and "default.log" (e.g., C:\Program Data\Bromium\BMS\Logs\default.log).

Note: Follow the instructions included with the event server.

Check Contents

Ask the site representatives if they have developed and implemented a solution for forwarding the contents of "worker.log" and "default.log" to a central log server.

If the BEC and Bromium vSentry does not generate an event and forward to the events server when anomalies in the operation of security functions of the BEC or Bromium vSentry application are discovered, this is a finding.

Vulnerability Number

V-80471

Documentable

False

Rule Version

BROM-00-001155

Severity Override Guidance

Ask the site representatives if they have developed and implemented a solution for forwarding the contents of "worker.log" and "default.log" to a central log server.

If the BEC and Bromium vSentry does not generate an event and forward to the events server when anomalies in the operation of security functions of the BEC or Bromium vSentry application are discovered, this is a finding.

Check Content Reference

M

Target Key

3375

Comments