SV-213333r506897_rule
V-213333
SRG-APP-000276
MCAC-TE-000107
CAT II
10
If an ATD server is not being used in the environment, this is Not Applicable.
From the ePO server console System Tree, select the "Systems" tab.
Select "This Group and All Subgroups".
Select the asset.
Select "Actions".
Select "Agent".
Select "Modify Policies on a Single System".
From the product pull-down list, select Solidcore 8.x: Application Control.
From the "Policy" column, select the policy associated with the Category "Application Control Options (Windows)" that is specific for the asset being reviewed.
Select the "Reputation" tab.
In the drop-down selection box of the "Advanced Threat Defense (ATD) settings: Send binaries" option, select "Might be Trusted".
Click "Save".
This requirement is only applicable to Windows platforms. For MAC and Linux platforms, this is Not Applicable.
If an ATD server is not being used in the environment, this is Not Applicable.
From the ePO server console System Tree, select the "Systems" tab.
Select "This Group and All Subgroups".
Select the asset to be validated.
Select "Actions".
Select "Agent".
Select "Modify Policies on a Single System".
From the product pull-down list, select Solidcore 8.x: Application Control. From the "Policy" column, select the policy associated with the Category "Application Control Options (Windows)" that is specific for the asset being reviewed.
Select the "Reputation" tab.
If the option for sending binaries for analysis under the "Advanced Threat Defense (ATD) settings" is selected, verify the level of binaries to be sent for analysis is "Might be Trusted" and below.
If the level of binaries to be sent for analysis is not "Might be Trusted", this is a finding.
V-213333
False
MCAC-TE-000107
This requirement is only applicable to Windows platforms. For MAC and Linux platforms, this is Not Applicable.
If an ATD server is not being used in the environment, this is Not Applicable.
From the ePO server console System Tree, select the "Systems" tab.
Select "This Group and All Subgroups".
Select the asset to be validated.
Select "Actions".
Select "Agent".
Select "Modify Policies on a Single System".
From the product pull-down list, select Solidcore 8.x: Application Control. From the "Policy" column, select the policy associated with the Category "Application Control Options (Windows)" that is specific for the asset being reviewed.
Select the "Reputation" tab.
If the option for sending binaries for analysis under the "Advanced Threat Defense (ATD) settings" is selected, verify the level of binaries to be sent for analysis is "Might be Trusted" and below.
If the level of binaries to be sent for analysis is not "Might be Trusted", this is a finding.
M
3982