Skip to content
Catalogs
XCCDF
Trellix Application Control 8.x Security Technical Implementation Guide
SRG-APP-000386
The organization-specific Rules policy must only include executable and dll files that are associated with applications as allowed by the organizations written policy.
The organization-specific Rules policy must only include executable and dll files that are associated with applications as allowed by the organizations written policy. An XCCDF Rule
The organization-specific Rules policy must only include executable and dll files that are associated with applications as allowed by the organizations written policy.
Medium Severity
<VulnDiscussion>To ensure Solidcore clients are only configured to STIG and organization-specific settings, organization-specific ePO policies must be applied to all organization workstation endpoints.
The Trellix Application Control installs with two Default Rules policies.
The Trellix Default Rules policy includes the whitelist for commonly used applications to the platform.
The Trellix Applications Default Rules policy include the whitelist for Trellix applications.
Both of these policies are at the "My Organization" level of the System Tree and must be inherited by all branches of the System Tree.
Organization-specific applications would be whitelisted with an organization-specific policy combined with the two Default policies into one effective policy.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>