SV-234801r622137_rule
V-234801
SRG-OS-000191-GPOS-00080
SLES-15-010001
CAT II
10
Install and enable the latest McAfee ENSLTP.
Per OPORD 16-0080, the preferred intrusion detection system is McAfee Host Intrusion Prevention System (HIPS) in conjunction with SELinux. McAfee Endpoint Security for Linux (ENSL) is an approved alternative to McAfee Virus Scan Enterprise (VSE) and HIPS.
Procedure:
Verify the SUSE operating system deploys ENSLTP.
Check that the following package has been installed:
# rpm -qa | grep isectp
If the "isectp" package is not installed, this is a finding.
Verify that the daemon is running:
# ps -ef | grep -i “isectpd”
If the daemon is not running, this is a finding.
V-234801
False
SLES-15-010001
Per OPORD 16-0080, the preferred intrusion detection system is McAfee Host Intrusion Prevention System (HIPS) in conjunction with SELinux. McAfee Endpoint Security for Linux (ENSL) is an approved alternative to McAfee Virus Scan Enterprise (VSE) and HIPS.
Procedure:
Verify the SUSE operating system deploys ENSLTP.
Check that the following package has been installed:
# rpm -qa | grep isectp
If the "isectp" package is not installed, this is a finding.
Verify that the daemon is running:
# ps -ef | grep -i “isectpd”
If the daemon is not running, this is a finding.
M
5274