| Checked | Name | Title |
|---|
| ☐ | SV-242167r856969_rule | To protect against unauthorized data mining, the TPS must prevent code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields. |
| ☐ | SV-242168r856970_rule | To protect against unauthorized data mining, the TPS must prevent code injection attacks launched against application objects including, at a minimum, application URLs and application code. |
| ☐ | SV-242169r856971_rule | To protect against unauthorized data mining, the TPS must prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields. |
| ☐ | SV-242170r856972_rule | To protect against unauthorized data mining, the TPS must detect code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields. |
| ☐ | SV-242171r856973_rule | To protect against unauthorized data mining, the TPS must detect code injection attacks launched against application objects including, at a minimum, application URLs and application code. |
| ☐ | SV-242172r856974_rule | To protect against unauthorized data mining, the TPS must detect SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields. |
| ☐ | SV-242173r840498_rule | The Trend Micro TippingPoint Security Management System (SMS) must be configured to send security IPS policy to the Trend Micro Threat Protection System (TPS). |
| ☐ | SV-242175r710068_rule | The Trend Micro TPS must immediately use updates made to policy filters, rules, signatures, and anomaly analysis algorithms for traffic detection and prevention functions which are all contained in the Digital Vaccine (DV) updates. |
| ☐ | SV-242176r1028382_rule | The TPS must provide audit record generation capability for detection events based on implementation of policy filters, rules, signatures, and anomaly analysis. |
| ☐ | SV-242177r710074_rule | The TPS must provide audit record generation capability for events where communication traffic is blocked or restricted based on policy filters, rules, signatures, and anomaly analysis. |
| ☐ | SV-242186r710101_rule | In the event of a logging failure caused by the lack of audit record storage capacity, the SMS must continue generating and storing audit records, overwriting the oldest audit records in a first-in-first-out manner using Audit Log maintenance. |
| ☐ | SV-242187r710104_rule | The SMS and TPS must provide log information in a format that can be extracted and used by centralized analysis tools. |
| ☐ | SV-242188r1028381_rule | The SMS must be configured to remove or disable nonessential capabilities on SMS and TPS, which are not required for operation or not related to IDPS functionality. |
| ☐ | SV-242189r839149_rule | The TPS must detect, at a minimum, mobile code that is unsigned or exhibiting unusual behavior, has not undergone a risk assessment, or is prohibited for use based on a risk assessment. |
| ☐ | SV-242190r839150_rule | The TPS must block any prohibited mobile code at the enclave boundary when it is detected. |
| ☐ | SV-242191r710116_rule | The TPS must fail to a secure state which maintains access control mechanisms when the IDPS hardware, software, or firmware fails on initialization/shutdown or experiences a sudden abort during normal operation (also known as "Fail closed"). |
| ☐ | SV-242192r997619_rule | The TPS must protect against or limit the effects of known types of denial-of-service (DoS) attacks by employing signatures. |
| ☐ | SV-242193r997620_rule | The TPS must block outbound traffic containing known and unknown denial-of-service (DoS) attacks by ensuring that security policies, signatures, rules, and anomaly detection techniques are applied to outbound communications traffic. |
| ☐ | SV-242194r840196_rule | The TPS must block outbound ICMP Destination Unreachable, Redirect, and Address Mask reply messages. |
| ☐ | SV-242195r840193_rule | The TPS must block malicious ICMP packets by properly configuring ICMP signatures and rules. |
| ☐ | SV-242196r1018783_rule | The TPS must automatically install updates to signature definitions, detection heuristics, and vendor-provided rules. |
| ☐ | SV-242197r1018784_rule | The SMS must install updates on the TPS for application software files, signature definitions, detection heuristics, and vendor-provided rules when new releases are available in accordance with organizational configuration management policy and procedures. |
| ☐ | SV-242198r839154_rule | The TPS must block malicious code. |
| ☐ | SV-242199r1018785_rule | The TPS must generate a log record so an alert can be configured to, at a minimum, the system administrator when malicious code is detected. |
| ☐ | SV-242201r856976_rule | The TPS must detect network services that have not been authorized or approved by the ISSO or ISSM, at a minimum, through use of a site-approved TPS device profile. |
| ☐ | SV-242202r856977_rule | The IDPS must generate an alert to the ISSM and ISSO, at a minimum, when unauthorized network services are detected. |
| ☐ | SV-242203r856978_rule | The IDPS must continuously monitor inbound communications traffic for unusual/unauthorized activities or conditions. |
| ☐ | SV-242204r856979_rule | The TPS must continuously monitor outbound communications traffic for unusual/unauthorized activities or conditions. |
| ☐ | SV-242205r971533_rule | The TPS must send an alert to, at a minimum, the ISSM and ISSO when intrusion detection events are detected which indicate a compromise or potential for compromise. |
| ☐ | SV-242206r971533_rule | The site must register with the Trend Micro TippingPoint Threat Management Center (TMC) in order to receive alerts on threats identified by authoritative sources (e.g., IAVMs or CTOs) are detected which indicate a compromise or potential for compromise. |