CCI-001774
Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Tanium must employ a deny-all, permit-by-exception (whitelist) policy to allow the execution of authorized software programs.
1 rule found Severity: Medium

2 rules found Severity: Low

2 rules found Severity: Low

2 rules found Severity: Low

2 rules found Severity: Low

2 rules found Severity: High

1 rule found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

The Apparmor module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs and limit the ability of non-privileged users to grant other users direct access to the contents of their home directories/folders.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

AIX must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
1 rule found Severity: Medium

The operating system must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
3 rules found Severity: Medium

Windows Server 2016 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
1 rule found Severity: Medium

The application must employ a deny-all, permit-by-exception (allowlist) policy to allow the execution of authorized software programs.
1 rule found Severity: Medium

A Trellix Application Control written policy must be documented to outline the organization-specific variables for application whitelisting.
1 rule found Severity: Medium

The configuration of features under Trellix Application Control Options policies Enforce feature control must be documented in the organizations written policy.
1 rule found Severity: Medium

The organizations written policy must include a process for how whitelisted applications are deemed to be allowed.
1 rule found Severity: Medium

The organizations written policy must include procedures for how often the whitelist of allowed applications is reviewed.
1 rule found Severity: Medium

1 rule found Severity: High

The organization-specific Rules policy must only include executable and dll files that are associated with applications as allowed by the organizations written policy.
1 rule found Severity: Medium

The Trellix Application Control Options Reputation-Based Execution settings, if enabled, must be configured to allow Most Likely Trusted or Known Trusted only.
1 rule found Severity: Medium

Organization-specific Trellix Applications Control Options policies must be created and applied to all endpoints.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Trellix Application Control Options policy End User Notification, if configured by organization, must have all default variables replaced with the organization-specific data.
1 rule found Severity: Medium

The Trellix Application Control Options policies Enforce feature control memory protection must be enabled.
1 rule found Severity: Medium

Enabled features under Trellix Application Control Options policies Enforce feature control must not be configured unless documented in written policy and approved by ISSO/ISSM.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Trellix Application Control Options Inventory interval option must be configured to pull inventory from endpoints on a regular basis not to exceed seven days.
1 rule found Severity: Medium

The Trellix Applications Default Rules policy must be part of the effective rules policy applied to every endpoint.
1 rule found Severity: Medium

A copy of the Trellix Default Rules policy must be part of the effective rules policy applied to every endpoint.
1 rule found Severity: Medium

The organization-specific Rules policies must be part of the effective rules policy applied to all endpoints.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Throttling settings must be enabled and configured to settings according to organizations requirements.
1 rule found Severity: Medium

1 rule found Severity: Medium

The application must employ a deny-all, permit-by-exception (whitelist) policy to allow the execution of authorized software programs.
1 rule found Severity: Medium

The Infrastructure as a Service (IaaS)/Platform as a Service (PaaS)/Software as a Service (SaaS) must register the service/application with the DOD DMZ/IAP allowlist for internet-facing inbound and outbound traffic.
1 rule found Severity: Medium

The container platform registry must employ a deny-all, permit-by-exception (whitelist) policy to allow only authorized container images in the container platform.
1 rule found Severity: Medium

1 rule found Severity: High

Windows Server 2019 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
1 rule found Severity: Medium

Windows Server 2022 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
1 rule found Severity: Medium

Images stored within the container registry must contain only images to be run as containers within the container platform.
1 rule found Severity: Medium

The OL 8 fapolicy module must be configured to employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
1 rule found Severity: Medium

The SUSE operating system Apparmor tool must be configured to control whitelisted applications and user home directory access control.
1 rule found Severity: Medium

SUSE operating system AppArmor tool must be configured to control whitelisted applications and user home directory access control.
1 rule found Severity: Medium

The VMM must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs and guest VMs.
1 rule found Severity: Medium

1 rule found Severity: High
