SV-213331r506897_rule
V-213331
SRG-APP-000386
MCAC-TE-000105
CAT II
10
If Reputation-Based Execution settings is not enabled, this check is Not Applicable.
From the ePO server console System Tree, select the "Systems" tab.
Select "This Group and All Subgroups".
Select the asset.
Select "Actions".
Select "Agent".
Select "Modify Policies on a Single System".
From the product pull-down list, select Solidcore 8.x: Application Control.
From the "Policy" column, select the policy associated with the Category "Application Control Options (Windows)" that is specific for the asset being reviewed.
Select the "Reputation" tab.
Place a check in the "Reputation-Based Execution Settings: Allow binaries with" check box and select "Most Likely Trusted" from the drop-down selection box.
Click "Save".
This requirement is only applicable to Windows platforms. For MAC and Linux platforms, this is Not Applicable.
If Reputation-Based Execution settings is not enabled, this check is Not Applicable.
From the ePO server console System Tree, select the "Systems" tab.
Select "This Group and All Subgroups".
Select the asset(s) that need the organization-specific policy.
Select "Actions".
Select "Agent".
Select "Modify Policies on a Single System".
From the product pull-down list, select Solidcore 8.x: Application Control.
From the "Policy" column, select the policy associated with the Category "Application Control Options (Windows)" that is specific for the asset being reviewed.
Select the "Reputation" tab.
Verify the "Reputation-Based Execution Settings" is configured to allow binaries with "Most Likely Trusted" and above.
If the allow binaries "Most Likely Trusted" and above is not selected for "Reputation-Based Execution Settings", this is a finding.
V-213331
False
MCAC-TE-000105
This requirement is only applicable to Windows platforms. For MAC and Linux platforms, this is Not Applicable.
If Reputation-Based Execution settings is not enabled, this check is Not Applicable.
From the ePO server console System Tree, select the "Systems" tab.
Select "This Group and All Subgroups".
Select the asset(s) that need the organization-specific policy.
Select "Actions".
Select "Agent".
Select "Modify Policies on a Single System".
From the product pull-down list, select Solidcore 8.x: Application Control.
From the "Policy" column, select the policy associated with the Category "Application Control Options (Windows)" that is specific for the asset being reviewed.
Select the "Reputation" tab.
Verify the "Reputation-Based Execution Settings" is configured to allow binaries with "Most Likely Trusted" and above.
If the allow binaries "Most Likely Trusted" and above is not selected for "Reputation-Based Execution Settings", this is a finding.
M
3982