STIGQter STIGQter: STIG Summary: McAfee MOVE Agentless 3.6.1 Security Virtual Appliance STIG Version: 1 Release: 5 Benchmark Date: 28 Oct 2016:

The McAfee MOVE AV Agentless SVA policy must be configured with, and managed by, the HBSS ePO server.

DISA Rule

SV-56787r2_rule

Vulnerability Number

V-43957

Group Title

AV-MOVE-SVA-001-McAfee MOVE SVA policy management

Rule Version

AV-MOVE-SVA-001

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Obtain the McAfee Agent install files from the McAfee ePO server and install onto the McAfee SVA, following the same procedures as for any other Linux system being managed by the McAfee ePO server.

After installation, from the ePO server console System Tree, select "My Organization". Select the Systems tab. Find and double-click on the asset representing the McAfee MOVE Security Virtual Appliance (SVA) to open its properties.

Under the System Properties tab, ensure the "Last Communication" date is within the time period designated by the "Agent-to-Server Communication Interval:" under the McAfee Agent tab.

Under the System Properties tab, next to the Installed Products field, ensure MOVE AV [Agentless]" is listed as an installed product.

Check Contents

NOTE: MOVE Agentless 3.61 Security Virtual Appliance (SVA) comes pre-installed with McAfee Agent 4.8 and requires that the McAfee Agent 4.8 Extension already be installed on the ePO 5.0.x Server. ePO 4.6 environments must upgrade to the McAfee Agent 4.8 Extension prior to deployment of the MOVE Agentless 3.61 SVA.

From the ePO server console System Tree, select "My Organization". Select the Systems tab. To show all systems in the System Tree, select "This Group and All Subgroups" from the "Preset:" drop-down list. From the list of systems, locate the asset representing the McAfee MOVE Security Virtual Appliance (SVA).

If the system designated as the McAfee MOVE Security Virtual Appliance (SVA) is not in the ePO server System Tree, this is a finding.

If the system designated as the McAfee MOVE Security Virtual Appliance (SVA) is in the ePO server System Tree, click on the system to open the System Information page.

On the System Information page, verify "MOVE AV [Agentless]" is listed as an Installed Product.

If the system does not show MOVE AV [Agentless] listed as an installed product, this is a finding.

Vulnerability Number

V-43957

Documentable

False

Rule Version

AV-MOVE-SVA-001

Severity Override Guidance

NOTE: MOVE Agentless 3.61 Security Virtual Appliance (SVA) comes pre-installed with McAfee Agent 4.8 and requires that the McAfee Agent 4.8 Extension already be installed on the ePO 5.0.x Server. ePO 4.6 environments must upgrade to the McAfee Agent 4.8 Extension prior to deployment of the MOVE Agentless 3.61 SVA.

From the ePO server console System Tree, select "My Organization". Select the Systems tab. To show all systems in the System Tree, select "This Group and All Subgroups" from the "Preset:" drop-down list. From the list of systems, locate the asset representing the McAfee MOVE Security Virtual Appliance (SVA).

If the system designated as the McAfee MOVE Security Virtual Appliance (SVA) is not in the ePO server System Tree, this is a finding.

If the system designated as the McAfee MOVE Security Virtual Appliance (SVA) is in the ePO server System Tree, click on the system to open the System Information page.

On the System Information page, verify "MOVE AV [Agentless]" is listed as an Installed Product.

If the system does not show MOVE AV [Agentless] listed as an installed product, this is a finding.

Check Content Reference

M

Responsibility

System Administrator

Target Key

2578

Comments