II - Mission Support Classified
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000120
<GroupDescription></GroupDescription>Group -
The UEM server must protect audit information from unauthorized deletion.
<VulnDiscussion>If audit data were to become compromised, then forensic analysis and discovery of the true source of potentially malicious sy...Rule Medium Severity -
SRG-APP-000125
<GroupDescription></GroupDescription>Group -
The UEM server must back up audit records at least every seven days onto a log management server.
<VulnDiscussion>Protection of log data includes ensuring log data is not accidentally lost or deleted. Backing up audit records to a differen...Rule Medium Severity -
SRG-APP-000131
<GroupDescription></GroupDescription>Group -
The UEM server must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
<VulnDiscussion>Changes to any software components can have significant effects on the overall security of the application. Verifying softwar...Rule Medium Severity -
SRG-APP-000133
<GroupDescription></GroupDescription>Group -
The UEM server must limit privileges to change the software resident within software libraries.
<VulnDiscussion>If the application were to allow any user to make changes to software libraries, then those changes might be implemented with...Rule Medium Severity -
SRG-APP-000141
<GroupDescription></GroupDescription>Group -
The UEM server must be configured to disable non-essential capabilities.
<VulnDiscussion>It is detrimental for applications to provide, or install by default, functionality exceeding requirements or mission objecti...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.