STIGQter STIGQter: STIG Summary:

Trellix Application Control 8.x Security Technical Implementation Guide

Version: 3

Release: 2 Benchmark Date: 02 Jul 2025

CheckedNameTitle
SV-213316r961479_ruleA Trellix Application Control written policy must be documented to outline the organization-specific variables for application whitelisting.
SV-213317r1015267_ruleThe use of a Solidcore 8.x local Command Line Interface (CLI) Access Password must be documented in the organizations written policy.
SV-213318r1015874_ruleThe Solidcore client Command Line Interface (CLI) Access password complexity requirements must be documented in the organizations written policy.
SV-213319r961029_ruleThe Solidcore client Command Line Interface (CLI) Access Password protection process must be documented in the organizations written policy.
SV-213320r1043190_ruleThe requirement for scheduled Solidcore client Command Line Interface (CLI) Access Password changes must be documented in the organizations written policy.
SV-213321r986211_ruleThe process by which the Solidcore client Command Line Interface (CLI) Access Password is made available to administrators when needed must be documented in the organizations written policy.
SV-213322r1015876_ruleThe Trellix Application Control Options Advanced Threat Defense (ATD) settings, if being used, must be confined to the organizations enclave.
SV-213323r961479_ruleThe configuration of features under Trellix Application Control Options policies Enforce feature control must be documented in the organizations written policy.
SV-213324r961479_ruleThe organizations written policy must include a process for how whitelisted applications are deemed to be allowed.
SV-213325r961479_ruleThe organizations written policy must include procedures for how often the whitelist of allowed applications is reviewed.
SV-213326r961479_ruleThe Solidcore client must be enabled.
SV-213327r961470_ruleThe Solidcore client Command Line Interface (CLI) must be in lockdown mode.
SV-213328r961479_ruleThe Solidcore client Command Line Interface (CLI) Access Password must be changed from the default.
SV-213329r961479_ruleThe organization-specific Rules policy must only include executable and dll files that are associated with applications as allowed by the organizations written policy.
SV-213330r1015877_ruleThe Trellix Application Control Options Reputation setting must be configured to use the Trellix Global Threat Intelligence (Trellix GTI) option.
SV-213331r961479_ruleThe Trellix Application Control Options Reputation-Based Execution settings, if enabled, must be configured to allow Most Likely Trusted or Known Trusted only.
SV-213332r1015878_ruleThe Trellix Application Control Options Advanced Threat Defense (ATD) settings must not be enabled unless an internal ATD is maintained by the organization.
SV-213333r1015879_ruleThe Trellix Application Control Options Advanced Threat Defense (ATD) settings, if being used, must be configured to send all binaries with a reputation of Might be Trusted and below for analysis.
SV-213334r1015880_ruleThe Trellix Application Control Options Advanced Threat Defense (ATD) settings, if being used, must be configured to only send binaries with a size of 5MB or less.
SV-213336r961479_ruleThe Trellix Application Control Options policy must be configured to disable Self-Approval.
SV-213337r961479_ruleThe Trellix Application Control Options policy End User Notification, if configured by organization, must have all default variables replaced with the organization-specific data.
SV-213338r961479_ruleThe Trellix Application Control Options policies Enforce feature control memory protection must be enabled.
SV-213339r961479_ruleEnabled features under Trellix Application Control Options policies Enforce feature control must not be configured unless documented in written policy and approved by ISSO/ISSM.
SV-213340r961479_ruleThe Trellix Application Control Options Inventory option must be configured to hide OS Files.
SV-213341r961479_ruleThe Trellix Application Control Options Inventory interval option must be configured to pull inventory from endpoints on a regular basis not to exceed seven days.
SV-213342r961479_ruleThe Trellix Applications Default Rules policy must be part of the effective rules policy applied to every endpoint.
SV-213343r961479_ruleA copy of the Trellix Default Rules policy must be part of the effective rules policy applied to every endpoint.
SV-213344r961479_ruleThe organization-specific Rules policies must be part of the effective rules policy applied to all endpoints.
SV-213345r961479_ruleThe organization-specific Solidcore Client Policies must be created and applied to all endpoints.
SV-213346r961479_ruleThe Throttling settings must be enabled and configured to settings according to organizations requirements.
SV-213347r961479_ruleThe Solidcore Client Exception Rules must be documented in the organizations written policy.