STIGQter STIGQter: STIG Summary: Bromium Secure Platform 4.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 May 2018:

If the Host Based Security System (HBSS) is not installed to monitor the Bromium Enterprise Controller (BEC) application, processes, and registry settings, the Bromium Protection agent must be installed on the BEC server.

DISA Rule

SV-95169r1_rule

Vulnerability Number

V-80465

Group Title

SRG-APP-000450

Rule Version

BROM-00-001080

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

If HBSS is not installed to monitor the BEC application, processes, and registry settings, install the Bromium Protection agent on the BEC server.

1. Install the Bromium agent on the BEC server (follow the on-screen instructions when deploying the ".msi" installation package).
2. Add the BEC server to a device group (this group may contain other/additional BEC servers).
3. Enable the monitoring policy for the BEC server.

Check Contents

If HBSS is installed and configured to monitor the BEC application, processes, and registry settings, this is not a finding.

1. From the management console, select "Devices".
2. Click on "Add Filter" and select "Contains Text".
3. Click on the down arrow and enter the device name to search for the BEC server.
4. Once the desired BEC server is located, click on the device and inspect the "Monitoring Version" column to verify that the monitoring module is installed and enabled.

If the Bromium Protection agent is not installed and configured on the BEC server, this is a finding.

Vulnerability Number

V-80465

Documentable

False

Rule Version

BROM-00-001080

Severity Override Guidance

If HBSS is installed and configured to monitor the BEC application, processes, and registry settings, this is not a finding.

1. From the management console, select "Devices".
2. Click on "Add Filter" and select "Contains Text".
3. Click on the down arrow and enter the device name to search for the BEC server.
4. Once the desired BEC server is located, click on the device and inspect the "Monitoring Version" column to verify that the monitoring module is installed and enabled.

If the Bromium Protection agent is not installed and configured on the BEC server, this is a finding.

Check Content Reference

M

Target Key

3375

Comments