Skip to content

HYCU Protege Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000092-NDM-000224

    Group
  • The HYCU virtual appliance must initiate session auditing upon startup.

    It is essential for security personnel to know what is being done, what was attempted, where it was done, when it was done, and by whom it was done to compile an accurate risk assessment. Associati...
    Rule Medium Severity
  • SRG-APP-000319-NDM-000283

    Group
  • SRG-APP-000505-NDM-000322

    Group
  • The HYCU virtual appliance must generate audit records showing starting and ending time for administrator access to the system.

    It is essential for security personnel to know what is being done, what was attempted, where it was done, when it was done, and by whom it was done to compile an accurate risk assessment. Associati...
    Rule Medium Severity
  • SRG-APP-000357-NDM-000293

    Group
  • The HYCU virtual appliance must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.

    To ensure network devices have a sufficient storage capacity in which to write the audit logs, they must be able to allocate audit record storage capacity. The task of allocating audit record stora...
    Rule Medium Severity
  • SRG-APP-000516-NDM-000341

    Group
  • The HYCU virtual appliance must support organizational requirements to conduct backups of information system documentation, including security-related documentation, when changes occur or weekly, whichever is sooner.

    Information system backup is a critical step in maintaining data assurance and availability. Information system and security-related documentation contains information pertaining to system configur...
    Rule Medium Severity
  • SRG-APP-000515-NDM-000325

    Group
  • The HYCU virtual appliance must off-load audit records onto a different system or media than the system being audited.

    Information system backup is a critical step in maintaining data assurance and availability. Information system and security-related documentation contains information pertaining to system configur...
    Rule Medium Severity
  • SRG-APP-000360-NDM-000295

    Group
  • SRG-APP-000120-NDM-000237

    Group
  • SRG-APP-000121-NDM-000238

    Group
  • The HYCU virtual appliance must protect audit tools from unauthorized access, modification, and deletion.

    Protecting audit data also includes identifying and protecting the tools used to view and manipulate log data. Therefore, protecting audit tools is necessary to prevent unauthorized operation on au...
    Rule Medium Severity
  • SRG-APP-000516-NDM-000351

    Group
  • The HYCU virtual appliance must be running a release that is currently supported by the vendor.

    Network devices running an unsupported operating system lack current security fixes required to mitigate the risks associated with recent vulnerabilities.
    Rule High Severity
  • SRG-APP-000516-NDM-000344

    Group
  • SRG-APP-000142-NDM-000245

    Group
  • SRG-APP-000156-NDM-000250

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules