STIGQter STIGQter: STIG Summary: Bromium Secure Platform 4.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 May 2018:

The Bromium vSentry client must automatically capture and forward payloads (Malware Manifest) that were downloaded and determined to be malicious to the management console.

DISA Rule

SV-95143r1_rule

Vulnerability Number

V-80439

Group Title

SRG-APP-000295

Rule Version

BROM-00-000650

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Modify the base policy to ensure that the micro-VM will terminate the user session upon the detection of malicious activity.

1. Using the management console, navigate to "Policies" and select the base policy.
2. Navigate to "Security".
3. Navigate to and enable the check box and radio button for the "Generate isolated threat malware manifests?" policy setting.
4. Click "Save and Deploy".

Check Contents

Review base policy to ensure that the micro-virtual machine (VM) will capture the malware manifest upon the detection of malicious activity.

1. Using the management console, navigate to "Policies" and select the base policy.
2. Navigate to "Security".
3. Navigate to and inspect the "Generate isolated threat malware manifests?" policy setting.

If the Bromium vSentry client is not configured to automatically capture and forward payloads that were downloaded and determined to be malicious to the management console, this is a finding.

Vulnerability Number

V-80439

Documentable

False

Rule Version

BROM-00-000650

Severity Override Guidance

Review base policy to ensure that the micro-virtual machine (VM) will capture the malware manifest upon the detection of malicious activity.

1. Using the management console, navigate to "Policies" and select the base policy.
2. Navigate to "Security".
3. Navigate to and inspect the "Generate isolated threat malware manifests?" policy setting.

If the Bromium vSentry client is not configured to automatically capture and forward payloads that were downloaded and determined to be malicious to the management console, this is a finding.

Check Content Reference

M

Target Key

3375

Comments