The organization-specific Rules policy must only include executable and dll files that are associated with applications as allowed by the organizations written policy.
An XCCDF Rule
Description
<VulnDiscussion>To ensure Solidcore clients are only configured to STIG and organization-specific settings, organization-specific ePO policies must be applied to all organization workstation endpoints. The Trellix Application Control installs with two Default Rules policies. The Trellix Default Rules policy includes the whitelist for commonly used applications to the platform. The Trellix Applications Default Rules policy include the whitelist for Trellix applications. Both of these policies are at the "My Organization" level of the System Tree and must be inherited by all branches of the System Tree. Organization-specific applications would be whitelisted with an organization-specific policy combined with the two Default policies into one effective policy.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-213329r944834_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Obtain the organization's written policy for the Trellix Application Control software from the System or ePO Administrator.
From the ePO server console System Tree, select the "Systems" tab.
Select "This Group and All Subgroups".
Select the asset.