A copy of the Trellix Default Rules policy must be part of the effective rules policy applied to every endpoint.
An XCCDF Rule
Description
<VulnDiscussion>To ensure Solidcore clients are only configured to STIG and organization-specific settings, an organization-specific ePO policies must be applied to all organization workstation endpoints. The Trellix Application Control installs with two Default Rules policies. The Trellix Default Rules policy includes the whitelist for commonly used applications to the platform. The Trellix Applications Default Rules policy include the whitelist for Trellix applications. Both of these policies are at the My Organization level of the System Tree and must be inherited by all branches of the System Tree. Organization-specific applications would be whitelisted with an organization-specific policy combined with the two Default policies into one effective policy.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-213343r944861_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
From the ePO server console System Tree, select the "Systems" tab.
Select "This Group and All Subgroups".
Select the asset.
Select "Actions".
Select "Agent".