Trend Micro Deep Security 9.x Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates +85 −85
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 85
- V-241108 Medium Trend Deep Security must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
- V-241109 Medium Trend Deep Security must initiate a session lock after a 15-minute period of inactivity.
- V-241110 Medium Trend Deep Security must provide automated mechanisms for supporting account management functions.
- V-241111 Medium Trend Deep Security must automatically audit account creation.
- V-241112 Medium Trend Deep Security must automatically audit account modification.
- V-241113 Medium Trend Deep Security must automatically audit account disabling actions.
- V-241114 Medium Trend Deep Security must automatically audit account removal actions.
- V-241115 Medium Trend Deep Security must enforce approved authorizations for controlling the flow of information within the system based on organization-defined information flow control policies.
- V-241116 Medium Trend Deep Security must enforce approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies.
- V-241117 Medium Trend Deep Security must enforce the limit of three consecutive invalid logon attempts by a user during a 15 minute time period.
- V-241118 Medium Trend Deep Security must scan all media used for system maintenance prior to use.
- V-241119 Medium Trend Deep Security must provide audit record generation capability for DoD-defined auditable events within all application components.
- V-241120 Medium Trend Deep Security must allow only the ISSM (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
- V-241121 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to access privileges occur.
- V-241122 Medium Trend Deep Security must initiate session auditing upon startup.
- V-241123 Medium Trend Deep Security must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
- V-241124 Medium Trend Deep Security must protect audit information from any type of unauthorized read access.
- V-241125 Medium Trend Deep Security must protect audit information from unauthorized modification.
- V-241126 Medium Trend Deep Security must protect audit information from unauthorized deletion.
- V-241127 Medium Trend Deep Security must protect audit tools from unauthorized access.
- V-241128 Medium Trend Deep Security must protect audit tools from unauthorized modification.
- V-241129 Medium Trend Deep Security must protect audit tools from unauthorized deletion.
- V-241130 Medium Trend Deep Security must back up audit records at least every seven days onto a different system or system component than the system or component being audited.
- V-241131 High Trend Deep Security must use cryptographic mechanisms to protect the integrity of audit information.
- V-241132 Medium Trend Deep Security must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
- V-241133 Medium Trend Deep Security must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
- V-241134 Medium Trend Deep Security must enforce a minimum 15-character password length.
- V-241135 Medium Trend Deep Security must enforce password complexity by requiring that at least one upper-case character be used.
- V-241136 Medium Trend Deep Security must enforce password complexity by requiring that at least one lower-case character be used.
- V-241137 Medium Trend Deep Security must enforce password complexity by requiring that at least one numeric character be used.
- V-241138 Medium Trend Deep Security must enforce password complexity by requiring that at least one special character be used.
- V-241139 Medium Trend Deep Security must enforce a 60-day maximum password lifetime restriction.
- V-241140 Medium Trend Deep Security must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).
- V-241141 Medium Trend Deep Security must terminate all network connections associated with a communications session at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity; and for user sessions (non-privileged session), the session must be terminated after 15 minutes of inactivity, except to fulfill documented and validated mission requirements.
- V-241142 Medium Trend Deep Security must isolate security functions from non-security functions.
- V-241143 Medium Trend Deep Security must restrict the ability of individuals to use information systems to launch organization-defined Denial of Service (DoS) attacks against other information systems.
- V-241144 Medium Trend Deep Security must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of Denial of Service (DoS) attacks.
- V-241145 Medium Trend Deep Security must automatically update malicious code protection mechanisms.
- V-241146 Medium Trend Deep Security must notify ISSO and ISSM of failed security verification tests.
- V-241147 Medium Trend Deep Security must update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy and procedures.
- V-241148 Medium Trend Deep Security must configure malicious code protection mechanisms to perform periodic scans of the information system every seven (7) days.
- V-241149 Medium Trend Deep Security must be configured to perform real-time malicious code protection scans of files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy.
- V-241150 Medium Trend Deep Security must be configured to block and quarantine malicious code upon detection, then send an immediate alert to appropriate individuals.
- V-241151 Medium Trend Deep Security must notify System Administrators and Information System Security Officers when accounts are created.
- V-241152 Medium Trend Deep Security must notify System Administrators and Information System Security Officers when accounts are modified.
- V-241153 Medium Trend Deep Security must notify System Administrators and Information System Security Officers for account disabling actions.
- V-241154 Medium Trend Deep Security must notify System Administrators and Information System Security Officers for account removal actions.
- V-241155 Medium Trend Deep Security must automatically audit account enabling actions.
- V-241156 Medium Trend Deep Security must notify SA and ISSO of account enabling actions.
- V-241157 Medium Trend Deep Security must audit the execution of privileged functions.
- V-241158 Medium Trend Deep Security must off-load audit records onto a different system or media than the system being audited.
- V-241159 Medium Trend Deep Security must provide an immediate warning to the SA and ISSO (at a minimum) when allocated audit record storage volume reaches 75% of repository maximum audit record storage capacity.
- V-241160 Medium Trend Deep Security must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.
- V-241161 Medium Trend Deep Security must alert the ISSO, ISSM, and other designated personnel (deemed appropriate by the local organization) when the unauthorized installation of software is detected.
- V-241162 Medium Trend Deep Security must prohibit user installation of software without explicit privileged status.
- V-241163 Medium Trend Deep Security must implement organization-defined automated security responses if baseline configurations are changed in an unauthorized manner.
- V-241164 Medium Trend Deep Security must enforce access restrictions associated with changes to application configuration.
- V-241165 Medium Trend Deep Security must audit the enforcement actions used to restrict access associated with changes to the application.
- V-241166 Medium Trend Deep Security must only allow the use of DoD PKI established certificate authorities for verification of the establishment of protected sessions.
- V-241167 Medium Trend Deep Security must maintain a separate execution domain for each executing process.
- V-241168 Medium Trend Deep Security must protect against or limit the effects of all types of Denial of Service (DoS) attacks by employing organization-defined security safeguards.
- V-241169 Medium Trend Deep Security must implement organization-defined security safeguards to protect its memory from unauthorized code execution.
- V-241170 Medium Trend Deep Security must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).
- V-241171 Medium Trend Deep Security detection application must detect network services that have not been authorized or approved by the organization-defined authorization or approval processes.
- V-241172 Medium Trend Deep Security must, when unauthorized network services are detected, log the event and alert the ISSO, ISSM, and other individuals designated by the local organization.
- V-241173 Medium Trend Deep Security must continuously monitor inbound communications traffic for unusual or unauthorized activities or conditions.
- V-241174 Medium Trend Deep Security must alert the ISSO, ISSM, and other individuals designated by the local organization when the following Indicators of Compromise (IOCs) or potential compromise are detected: real-time intrusion detection; threats identified by authoritative sources (e.g., CTOs); and Category I, II, IV, and VII incidents in accordance with CJCSM 6510.01B.
- V-241175 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to modify privileges occur.
- V-241176 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to modify security objects occur.
- V-241177 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to modify security levels occur.
- V-241178 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to delete privileges occur.
- V-241179 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to delete security objects occur.
- V-241180 Medium Trend Deep Security must generate audit records when successful/unsuccessful logon attempts occur.
- V-241181 Medium Trend Deep Security must generate audit records for privileged activities or other system-level access.
- V-241182 Medium Trend Deep Security must generate audit records when successful/unsuccessful accesses to objects occur.
- V-241183 Medium Trend Deep Security must generate audit records for all direct access to the information system.
- V-241184 Medium Trend Deep Security must generate audit records for all account creations, modifications, disabling, and termination events.
- V-241185 Medium Trend Deep Security must generate audit records for all kernel module load, unload, and restart events and, also for all program initiations.
- V-241186 Medium Trend Deep Security must, at a minimum, off-load interconnected systems in real time and off-load standalone systems weekly.
- V-241187 Medium Trend Deep Security must notify the system administrator when anomalies in the operation of the security functions are discovered.
- V-241188 Medium Trend Deep Security must implement security safeguards when integrity violations are discovered.
- V-241189 Medium Trend Deep Security must synchronize with Active Directory on a daily (or AO-defined) basis.
- V-241190 High Trend Deep Security must reside on a Web Server configured for multifactor authentication.
- V-241191 High Trend Deep Security must ensure users are authenticated with an individual authenticator prior to using a group authenticator.
- V-259713 High The version of Trend Deep Security running on the system must be a supported version.
Removed rules 85
- V-65857 Medium Trend Deep Security must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
- V-65859 Medium Trend Deep Security must initiate a session lock after a 15-minute period of inactivity.
- V-65861 Medium Trend Deep Security must automatically audit account creation.
- V-65863 Medium Trend Deep Security must automatically audit account modification.
- V-65865 Medium Trend Deep Security must automatically audit account disabling actions.
- V-65867 Medium Trend Deep Security must automatically audit account removal actions.
- V-65869 Medium Trend Deep Security must enforce approved authorizations for controlling the flow of information within the system based on organization-defined information flow control policies.
- V-65871 Medium Trend Deep Security must enforce approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies.
- V-65873 Medium Trend Deep Security must enforce the limit of three consecutive invalid logon attempts by a user during a 15 minute time period.
- V-65875 Medium Trend Deep Security must provide audit record generation capability for DoD-defined auditable events within all application components.
- V-65877 Medium Trend Deep Security must allow only the ISSM (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
- V-65879 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to access privileges occur.
- V-65881 Medium Trend Deep Security must initiate session auditing upon startup.
- V-65883 Medium Trend Deep Security must provide the capability for authorized users to capture, record, and log all content related to a user session.
- V-65885 Medium Trend Deep Security must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
- V-65887 Medium Trend Deep Security must protect audit information from any type of unauthorized read access.
- V-65889 Medium Trend Deep Security must protect audit information from unauthorized modification.
- V-65891 Medium Trend Deep Security must protect audit information from unauthorized deletion.
- V-65893 Medium Trend Deep Security must protect audit tools from unauthorized access.
- V-65895 Medium Trend Deep Security must protect audit tools from unauthorized modification.
- V-65897 Medium Trend Deep Security must protect audit tools from unauthorized deletion.
- V-65899 Medium Trend Deep Security must back up audit records at least every seven days onto a different system or system component than the system or component being audited.
- V-65901 High Trend Deep Security must use cryptographic mechanisms to protect the integrity of audit information.
- V-65903 Medium Trend Deep Security must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
- V-65905 Medium Trend Deep Security must scan all media used for system maintenance prior to use.
- V-65907 Medium Trend Deep Security must provide automated mechanisms for supporting account management functions.
- V-65909 Medium Trend Deep Security must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
- V-65913 High Trend Deep Security must ensure users are authenticated with an individual authenticator prior to using a group authenticator.
- V-65915 Medium Trend Deep Security must enforce a minimum 15-character password length.
- V-65917 Medium Trend Deep Security must enforce password complexity by requiring that at least one upper-case character be used.
- V-65919 Medium Trend Deep Security must enforce password complexity by requiring that at least one numeric character be used.
- V-65921 Medium Trend Deep Security must enforce password complexity by requiring that at least one special character be used.
- V-65925 Medium Trend Deep Security must enforce a 60-day maximum password lifetime restriction.
- V-65927 Medium Trend Deep Security must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).
- V-65929 Medium Trend Deep Security must terminate all network connections associated with a communications session at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity; and for user sessions (non-privileged session), the session must be terminated after 15 minutes of inactivity, except to fulfill documented and validated mission requirements.
- V-65931 Medium Trend Deep Security must isolate security functions from non-security functions.
- V-65933 Medium Trend Deep Security must restrict the ability of individuals to use information systems to launch organization-defined Denial of Service (DoS) attacks against other information systems.
- V-65935 Medium Trend Deep Security must manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of Denial of Service (DoS) attacks.
- V-65937 Medium Trend Deep Security must automatically update malicious code protection mechanisms.
- V-65939 Medium Trend Deep Security must notify ISSO and ISSM of failed security verification tests.
- V-65941 Medium Trend Deep Security must update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy and procedures.
- V-65943 Medium Trend Deep Security must configure malicious code protection mechanisms to perform periodic scans of the information system every seven (7) days.
- V-65945 Medium Trend Deep Security must be configured to perform real-time malicious code protection scans of files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy.
- V-65947 Medium Trend Deep Security must be configured to block and quarantine malicious code upon detection, then send an immediate alert to appropriate individuals.
- V-65949 Medium Trend Deep Security must notify System Administrators and Information System Security Officers when accounts are created.
- V-65951 Medium Trend Deep Security must notify System Administrators and Information System Security Officers when accounts are modified.
- V-65953 Medium Trend Deep Security must notify System Administrators and Information System Security Officers for account disabling actions.
- V-65955 Medium Trend Deep Security must notify System Administrators and Information System Security Officers for account removal actions.
- V-65957 Medium Trend Deep Security must automatically audit account enabling actions.
- V-65959 Medium Trend Deep Security must notify SA and ISSO of account enabling actions.
- V-65967 Medium Trend Deep Security must audit the execution of privileged functions.
- V-65969 Medium Trend Deep Security must off-load audit records onto a different system or media than the system being audited.
- V-65971 Medium Trend Deep Security must provide an immediate warning to the SA and ISSO (at a minimum) when allocated audit record storage volume reaches 75% of repository maximum audit record storage capacity.
- V-65973 Medium Trend Deep Security must provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts.
- V-65975 Medium Trend Deep Security must alert the ISSO, ISSM, and other designated personnel (deemed appropriate by the local organization) when the unauthorized installation of software is detected.
- V-65977 Medium Trend Deep Security must prohibit user installation of software without explicit privileged status.
- V-65979 Medium Trend Deep Security must implement organization-defined automated security responses if baseline configurations are changed in an unauthorized manner.
- V-65981 Medium Trend Deep Security must enforce access restrictions associated with changes to application configuration.
- V-65983 Medium Trend Deep Security must audit the enforcement actions used to restrict access associated with changes to the application.
- V-65985 Medium Trend Deep Security must only allow the use of DoD PKI established certificate authorities for verification of the establishment of protected sessions.
- V-65987 Medium Trend Deep Security must maintain a separate execution domain for each executing process.
- V-65989 Medium Trend Deep Security must protect against or limit the effects of all types of Denial of Service (DoS) attacks by employing organization-defined security safeguards.
- V-65991 Medium Trend Deep Security must implement organization-defined security safeguards to protect its memory from unauthorized code execution.
- V-65993 Medium Trend Deep Security must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).
- V-65995 Medium Trend Deep Security detection application must detect network services that have not been authorized or approved by the organization-defined authorization or approval processes.
- V-65997 Medium Trend Deep Security must, when unauthorized network services are detected, log the event and alert the ISSO, ISSM, and other individuals designated by the local organization.
- V-65999 Medium Trend Deep Security must continuously monitor inbound communications traffic for unusual or unauthorized activities or conditions.
- V-66001 Medium Trend Deep Security must alert the ISSO, ISSM, and other individuals designated by the local organization when the following Indicators of Compromise (IOCs) or potential compromise are detected: real-time intrusion detection; threats identified by authoritative sources (e.g., CTOs); and Category I, II, IV, and VII incidents in accordance with CJCSM 6510.01B.
- V-66005 Medium Trend Deep Security must notify the system administrator when anomalies in the operation of the security functions are discovered.
- V-66007 Medium Trend Deep Security must implement security safeguards when integrity violations are discovered.
- V-66011 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to modify privileges occur.
- V-66013 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to modify security objects occur.
- V-66017 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to modify security levels occur.
- V-66019 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to delete privileges occur.
- V-66023 Medium Trend Deep Security must generate audit records when successful/unsuccessful attempts to delete security objects occur.
- V-66025 Medium Trend Deep Security must generate audit records when successful/unsuccessful logon attempts occur.
- V-66027 Medium Trend Deep Security must generate audit records for privileged activities or other system-level access.
- V-66029 Medium Trend Deep Security must generate audit records when successful/unsuccessful accesses to objects occur.
- V-66031 Medium Trend Deep Security must generate audit records for all direct access to the information system.
- V-66033 Medium Trend Deep Security must generate audit records for all account creations, modifications, disabling, and termination events.
- V-66035 Medium Trend Deep Security must generate audit records for all kernel module load, unload, and restart events and, also for all program initiations.
- V-66037 Medium Trend Deep Security must, at a minimum, off-load interconnected systems in real time and off-load standalone systems weekly.
- V-66043 Medium Trend Deep Security must synchronize with Active Directory on a daily (or AO-defined) basis.
- V-66045 High Trend Deep Security must reside on a Web Server configured for multifactor authentication.
- V-66047 Medium Trend Deep Security must enforce password complexity by requiring that at least one lower-case character be used.
- RMF Control
- AC-10
- Severity
- M
- CCI
- CCI-000054
- Version
- TMDS-00-000005
- Vuln IDs
-
- V-241108
- V-65857
- Rule IDs
-
- SV-241108r879511_rule
- SV-80347
Checks: C-44341r678547_chk
Review the Trend Deep Security server configuration to ensure the number of concurrent sessions is limited to one. In the administration console go to: System Settings >> Security >> Number of concurrent sessions allowed per User Review the policy to ensure no more than 1 session is permitted. If more than 1 session is permitted this is a finding.
Fix: F-44300r678548_fix
Configure the Trend Deep Security server to limit the number of concurrent sessions to one. Set the current session limit to 1. Administration >> System Settings >> Security >> Number of concurrent sessions allowed per User >> 1
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000057
- Version
- TMDS-00-000010
- Vuln IDs
-
- V-241109
- V-65859
- Rule IDs
-
- SV-241109r879513_rule
- SV-80349
Checks: C-44342r678550_chk
Review the Trend Deep Security server configuration to ensure a session lock is initiated after a 15-minute period of inactivity. Review the application System Settings, to ensure the system timeout is set to 15 minutes or less. If the timeout session is not set to 15 minutes or less this is a finding. Administration >> System Settings >> Security >> User Security >> Session Timeout: 10 Minutes
Fix: F-44301r678551_fix
Configure the Trend Deep Security server to initiate a session lock after a 15-minute period of inactivity. Set the Session Timeout to 15 minutes or less. Administration >> Security >> User Security >> Session Timeout: 10 Minutes
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000015
- Version
- TMDS-00-000015
- Vuln IDs
-
- V-241110
- V-65907
- Rule IDs
-
- SV-241110r879522_rule
- SV-80397
Checks: C-44343r678553_chk
Review the Trend Deep Security server configuration to ensure automated mechanisms for supporting account management functions are automated. Interview the ISSO to determine a list of authorized users and their perspective roles supporting the application. Review the identified users within the following: Administration >> User Management >> Users >> Assign Role If the identified users do not match the roles assigned within the application this is a finding.
Fix: F-44302r678554_fix
Configure the Trend Deep Security server to provide automated mechanisms for supporting account management functions. Configure the user permissions according to their assigned roles within the organization. Administration >> User Management >> Users >> Assign Role
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-000018
- Version
- TMDS-00-000020
- Vuln IDs
-
- V-241111
- V-65861
- Rule IDs
-
- SV-241111r879525_rule
- SV-80351
Checks: C-44344r678556_chk
Review the Trend Deep Security server to ensure account creation is automatically audited. Verify "User Created" events is enabled by reviewing the following: Administration >> System Settings >> System Events >> Enable Event ID 650 User Created. Select: Record Select: Forward If "User Created" is not enabled this is a finding.
Fix: F-44303r678557_fix
Configure the Trend Deep Security server to automatically audit account creation. Enable "User Created" events by selecting the following: Administration >> System Settings >> System Events >> Enable Event ID 650 User Created. Select: Record Select: Forward
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001403
- Version
- TMDS-00-000025
- Vuln IDs
-
- V-241112
- V-65863
- Rule IDs
-
- SV-241112r879526_rule
- SV-80353
Checks: C-44345r678559_chk
Review the Trend Deep Security server configuration to ensure account creation is automatically audited. Verify "User Updated" events is enabled by reviewing the following: Administration >> System Settings >> System Events >> Enable Event ID 652 User Updated. Select: Record Select: Forward If "User Updated" is not enabled this is a finding.
Fix: F-44304r678560_fix
Configure the Trend Deep Security server to automatically audit account creation. Enable "User Updated" events by selecting the following: Administration >> System Settings >> System Events >> Enable Event ID 652 User Updated. Select: Record Select: Forward
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001404
- Version
- TMDS-00-000030
- Vuln IDs
-
- V-241113
- V-65865
- Rule IDs
-
- SV-241113r879527_rule
- SV-80355
Checks: C-44346r678562_chk
Review the Trend Deep Security server configuration to ensure account disabling actions are automatically audited. Verify "User Locked Out" events are enabled by reviewing the following: Administration >> System Settings >> System Events >> Enable Event ID 603 User Locked Out. Select: Record Select: Forward If "User Locked Out" is not enabled this is a finding.
Fix: F-44305r678563_fix
Configure the Trend Deep Security server to automatically audit account disabling actions. Enable "User Locked Out" events by selecting the following: Administration >> System Settings >> System Events >> Enable Event ID 603 User Locked Out. Select: Record Select: Forward
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001405
- Version
- TMDS-00-000035
- Vuln IDs
-
- V-241114
- V-65867
- Rule IDs
-
- SV-241114r879528_rule
- SV-80357
Checks: C-44347r678565_chk
Review the Trend Deep Security server configuration to ensure account removal actions are automatically audited. Verify "User Deleted" events are enabled by reviewing the following: Administration >> System Settings >> System Events >> Enable Event ID 651 User Deleted. Select: Record Select: Forward If "User Deleted" is not enabled this is a finding.
Fix: F-44306r678566_fix
Configure the Trend Deep Security server to automatically audit account removal actions. Enable "User Deleted" events by selecting the following: Administration >> System Settings >> System Events >> Enable Event ID 651 User Deleted. Select: Record Select: Forward
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001368
- Version
- TMDS-00-000040
- Vuln IDs
-
- V-241115
- V-65869
- Rule IDs
-
- SV-241115r879533_rule
- SV-80359
Checks: C-44348r678568_chk
Review the Trend Deep Security server configuration to ensure approved authorizations for controlling the flow of information within the system based on organization-defined information flow control policies are enforced. Interview the ISSO in order to identify all users with permissions to the application. The ISSO must identify each user along with their assigned role configured for the appropriate information systems allowed. Verify the information gathered against the application's, "Computer and Group Rights" for each "Role" created along with the users assigned. If the information gathered does not match the settings within the application this is a finding.
Fix: F-44307r678569_fix
Configure the Trend Deep Security server configuration to enforce approved authorizations for controlling the flow of information within the system based on organization-defined information flow control policies. Use the Computer and Group Rights panel to confer viewing, editing, deleting, Alert-dismissal, and Event tagging rights to Users in a Role. These rights can apply to all computers and computer groups or they can be restricted to only certain computers. To restrict access, select the "Selected Computers" radio button and put a check next to the computer groups and computers that Users in this Role will have access to. Administration >> User Management >> Roles Select a Role and click Properties >> Computer Rights
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- TMDS-00-000045
- Vuln IDs
-
- V-241116
- V-65871
- Rule IDs
-
- SV-241116r879534_rule
- SV-80361
Checks: C-44349r678571_chk
Review the Trend Deep Security server to ensure approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies are enforced. Interview the ISSO in order to identify all users with permissions to the application. The ISSO must identify each user along with their assigned role configured for the appropriate information systems allowed. Verify the information gathered against the application's, "Computer and Group Rights" for each "Role" created along with the users assigned. If the information gathered does not match the settings within the application this is a finding.
Fix: F-44308r678572_fix
Configure the Trend Deep Security server to enforce approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies. Use the Computer and Group Rights panel to confer viewing, editing, deleting, Alert-dismissal, and Event tagging rights to Users in a Role. These rights can apply to all computers and computer groups or they can be restricted to only certain computers. To restrict access, select the "Selected Computers" radio button and put a check next to the computer groups and computers that Users in this Role will have access to. Administration >> User Management >> Roles Select a Role and click Properties >> Computer Rights
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- TMDS-00-000050
- Vuln IDs
-
- V-241117
- V-65873
- Rule IDs
-
- SV-241117r879546_rule
- SV-80363
Checks: C-44350r678574_chk
Review the Trend Deep Security server configuration to ensure the limit of three consecutive invalid logon attempts by a user during a 15-minute time period is enforced. Verify the number of failed logon attempts. Go to Administration >> System Settings >> Security >> User Security >> Number of incorrect sign-in attempts allowed (before lock out): 3 If the number is greater than 3 this is a finding.
Fix: F-44309r678575_fix
Configure the Trend Deep Security server to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. Configure the number of failed logon attempts to 3. Administration >> System Settings >> Security >> User Security >> Number of incorrect sign-in attempts allowed (before lock out): 3
- RMF Control
- MA-3
- Severity
- M
- CCI
- CCI-000870
- Version
- TMDS-00-000055
- Vuln IDs
-
- V-241118
- V-65905
- Rule IDs
-
- SV-241118r879550_rule
- SV-80395
Checks: C-44351r678577_chk
Review the Trend Deep Security server to ensure all media used for system maintenance is scanned prior to use. Verify Anti-Malware is enabled on each server that is applicable to the accreditation boundary. Go to Computers. Right-click a computer from the list of systems, select properties Anti-Malware >> General Verify Configuration is set to "On" or "Inherit On". If Verify Configuration is set to "Off", this is a finding.
Fix: F-44310r678578_fix
Configure the Trend Deep Security server to scan all media used for system maintenance prior to use. The scope of Malware Scans can be controlled by editing the Malware Scan Configuration that is in effect on a computer. The Malware Scan Configuration determines which files and directories are included or excluded during a scan and which actions are taken if malware is detected on a computer (for example, clean, quarantine, or delete). There are two types of Malware Scan Configurations: - Manual/Scheduled Scan Configurations - Real-Time Scan Configurations To enable Anti-Malware functionality on a computer: Go to Computers. Right-click a computer from the list of systems, select properties Anti-Malware >> General Set Configuration to "On" or "Inherit On".
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- TMDS-00-000060
- Vuln IDs
-
- V-241119
- V-65875
- Rule IDs
-
- SV-241119r879559_rule
- SV-80365
Checks: C-44352r678580_chk
Review the Trend Deep Security server configuration to ensure audit record generation capability for DoD-defined auditable events within all application components is provided. Verify the Administration >> System Settings >> System Events, are set to “Record.” - capture successful and unsuccessful logon attempts, - privileged activities or other system level access, - starting and ending time for user access to the system - concurrent logons from different workstations - successful and unsuccessful accesses to objects - all program initiations, - all direct access to the information system, - all account creation, modification, disabling, and termination actions. If these settings are not set to “Record”, this is a finding.
Fix: F-44311r678581_fix
Configure Trend Deep Security to provide audit record generation capability for DoD-defined auditable events within all application components. Go to Administration >> System Settings >> System Events, and set the following settings to “Record.” 160 Authentication Failed 600 User Signed In 601 User Signed Out 602 User Timed Out 603 User Locked Out 604 User Unlocked 608 User Session Validation Failed 609 User Made Invalid Request 610 User Session Validated 611 User Viewed Firewall Event 613 User Viewed Intrusion Prevention Event 615 User Viewed System Event 616 User Viewed Integrity Monitoring Event 617 User Viewed Log Inspection Event 618 User Viewed Quarantined File Detail 619 User Viewed Anti-Malware Event 620 User Viewed Web Reputation Event 621 User Signed In As Tenant 650 User Created 651 User Deleted 652 User Updated 653 User Password Set 660 Role Created 661 Role Deleted 662 Role Updated 702 Credentials Generated 703 Credential Generation Failed
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000171
- Version
- TMDS-00-000065
- Vuln IDs
-
- V-241120
- V-65877
- Rule IDs
-
- SV-241120r879560_rule
- SV-80367
Checks: C-44353r678583_chk
Review the Trend Deep Security server to ensure only the ISSM (or individuals or roles appointed by the ISSM) is allowed to select which auditable events are to be audited. Verify the user roles and assigned permissions within the Administration >> User Management >> Roles >> Properties >> Other Rights. If a user role (e.g., Auditor) has any "View Only" for Alerts, Alert Configuration, Integrity Monitoring, and Log Inspection Rules, this is a finding.
Fix: F-44312r678584_fix
Configure the Trend Deep Security server to only allow the ISSM (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited. Configure the assigned permissions for user roles within the Administration >> User Management >> Roles >> Properties >> Other Rights. Set the following to "View Only" Alerts Alert Configuration Integrity Monitoring Log Inspection Rule
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000070
- Vuln IDs
-
- V-241121
- V-65879
- Rule IDs
-
- SV-241121r879561_rule
- SV-80369
Checks: C-44354r678586_chk
Review the Trend Deep Security server configuration to ensure only the ISSM (or individuals or roles appointed by the ISSM) is allowed to select which auditable events are to be audited. Verify the following events within the Administration >> System Settings >> System Events, are set to “Record.” 660 Role Created 661 Role Deleted 662 Role Updated 663 Roles Imported 664 Roles Exported If these settings are not set to “Record”, this is a finding.
Fix: F-44313r678587_fix
Configure the Trend Deep Security server to generate audit records when successful/unsuccessful attempts to access privileges occur. Go to Administration >> System Settings >> System Events, and set the following settings to “Record.” 660 Role Created 661 Role Deleted 662 Role Updated 663 Roles Imported 664 Roles Exported
- RMF Control
- AU-14
- Severity
- M
- CCI
- CCI-001464
- Version
- TMDS-00-000075
- Vuln IDs
-
- V-241122
- V-65881
- Rule IDs
-
- SV-241122r879562_rule
- SV-80371
Checks: C-44355r678589_chk
Review the Trend Deep Security server to ensure session auditing upon startup is initiated. Verify the following events within the Administration >> System Settings >> System Events, are set to “Record.” 600 User Signed In 601 User Signed Out 602 User Timed Out 603 User Locked Out 608 User Session Validation Failed 610 User Session Validated If these settings are not set to “Record”, this is a finding.
Fix: F-44314r678590_fix
Configure the Trend Deep Security server to initiate session auditing upon startup. Go to Administration >> System Settings >> System Events, and set the following settings to “Record.” 600 User Signed In 601 User Signed Out 602 User Timed Out 603 User Locked Out 608 User Session Validation Failed 610 User Session Validated
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000139
- Version
- TMDS-00-000085
- Vuln IDs
-
- V-241123
- V-65885
- Rule IDs
-
- SV-241123r879570_rule
- SV-80375
Checks: C-44356r678592_chk
Review the Trend Deep Security server configuration to ensure the ISSO and SA (at a minimum) are alerted in the event of an audit processing failure. Verify any audit processing failure events within Administration >> System Settings >> System Events, are set to “Forward” If these settings are not set to “Forward”, this is a finding.
Fix: F-44315r678593_fix
Configure the Trend Deep Security server to alert the ISSO and SA (at a minimum) in the event of an audit processing failure. Go to Administration >> System Settings >> System Events, and set the following settings to “Forward.” 0 Unknown Error 266 Warnings/Errors Cleared 609 User Made Invalid Request 740 Agent/Appliance Error 801 Error Dismissed 913 Automatic Diagnostic Package Error 923 Usage Information Package Error 997 Tagging Error 998 System Event Notification Error 999 Internal Software Error 1677 Trusted Platform Module Error
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000162
- Version
- TMDS-00-000090
- Vuln IDs
-
- V-241124
- V-65887
- Rule IDs
-
- SV-241124r879576_rule
- SV-80377
Checks: C-44357r678595_chk
Review the Trend Deep Security server configuration to ensure audit information from any type of unauthorized read access is protected. Interview the ISSO in order to identify all users and their permissions to the audit records. The ISSO must identify each user along with their assigned role configured for the appropriate information systems allowed. Verify the information gathered against the application's, "Computer and Group Rights" for each "Role" created along with the users assigned. If the information gathered does not match the settings within the application this is a finding.
Fix: F-44316r678596_fix
Configure the Trend Deep Security server to protect audit information from any type of unauthorized read access. Edit the audit permission according the local policy by modifying the roles under: Administration >> User Management >> Roles Select the applicable role. Click "Computer Rights" to modify user permissions. Next select “Other Rights” and modify accordingly.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000163
- Version
- TMDS-00-000095
- Vuln IDs
-
- V-241125
- V-65889
- Rule IDs
-
- SV-241125r879577_rule
- SV-80379
Checks: C-44358r678598_chk
Review the Trend Deep Security server configuration to ensure audit information is protected from unauthorized modification. Interview the ISSO in order to identify all users and their permissions to the audit records. The ISSO must identify each user along with their assigned role configured for the appropriate information systems allowed. Verify the information gathered against the application's, "Computer and Group Rights" for each "Role" created along with the users assigned. If the information gathered does not match the settings within the application this is a finding.
Fix: F-44317r678599_fix
Configure the Trend Deep Security server to protect audit information from unauthorized modification. Edit the audit permission according the local policy by modifying the roles under: Administration >> User Management >> Roles Select the applicable role. Click "Computer Rights" to modify user permissions. Next select “Other Rights” and modify accordingly.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-000164
- Version
- TMDS-00-000100
- Vuln IDs
-
- V-241126
- V-65891
- Rule IDs
-
- SV-241126r879578_rule
- SV-80381
Checks: C-44359r678601_chk
Review the Trend Deep Security server configuration to ensure audit information is protected from unauthorized deletion. Interview the ISSO in order to identify all users and their permissions to the audit records. The ISSO must identify each user along with their assigned role configured for the appropriate information systems allowed. Verify the information gathered against the application's, "Computer and Group Rights" for each "Role" created along with the users assigned. If the information gathered does not match the settings within the application this is a finding.
Fix: F-44318r678602_fix
Configure the Trend Deep Security server to protect audit information from unauthorized deletion. Edit the audit permission according the local policy by modifying the roles under: Administration >> User Management >> Roles Select the applicable role. Click "Computer Rights" to modify user permissions. Next select “Other Rights” and modify accordingly.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001493
- Version
- TMDS-00-000105
- Vuln IDs
-
- V-241127
- V-65893
- Rule IDs
-
- SV-241127r879579_rule
- SV-80383
Checks: C-44360r678604_chk
Review the Trend Deep Security server configuration to ensure audit tools are protected from unauthorized access. Interview the ISSO in order to identify all users and their permissions to the audit records. The ISSO must identify each user along with their assigned role configured for the appropriate information systems allowed. Verify the information gathered against the application's, "Computer and Group Rights" for each "Role" created along with the users assigned. If the information gathered does not match the settings within the application this is a finding.
Fix: F-44319r678605_fix
Configure the Trend Deep Security server to protect audit tools from unauthorized access. Edit the audit permission according the local policy by modifying the roles under: Administration >> User Management >> Roles Select the applicable role. Click "Computer Rights" to modify user permissions. Next select “Other Rights” and modify accordingly.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001494
- Version
- TMDS-00-000110
- Vuln IDs
-
- V-241128
- V-65895
- Rule IDs
-
- SV-241128r879580_rule
- SV-80385
Checks: C-44361r678607_chk
Review the Trend Deep Security server to ensure audit tools are protected from unauthorized modification. Interview the ISSO in order to identify all users and their permissions to the audit records. The ISSO must identify each user along with their assigned role configured for the appropriate information systems allowed. Verify the information gathered against the application's, "Computer and Group Rights" for each "Role" created along with the users assigned. If the information gathered does not match the settings within the application this is a finding.
Fix: F-44320r678608_fix
Configure the Trend Deep Security server to protect audit tools from unauthorized modification. Edit the audit permission according the local policy by modifying the roles under: Administration >> User Management >> Roles Select the applicable role. Click "Computer Rights" to modify user permissions. Next select “Other Rights” and modify accordingly.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001495
- Version
- TMDS-00-000115
- Vuln IDs
-
- V-241129
- V-65897
- Rule IDs
-
- SV-241129r879581_rule
- SV-80387
Checks: C-44362r678610_chk
Review the Trend Deep Security server configuration to ensure audit tools are protected from unauthorized deletion. Interview the ISSO in order to identify all users and their permissions to the audit records. The ISSO must identify each user along with their assigned role configured for the appropriate information systems allowed. Verify the information gathered against the application's, "Computer and Group Rights" for each "Role" created along with the users assigned. If the information gathered does not match the settings within the application this is a finding.
Fix: F-44321r678611_fix
Configure the Trend Deep Security server to protect audit tools from unauthorized deletion. Edit the audit permission according the local policy by modifying the roles under: Administration >> User Management >> Roles Select the applicable role. Click "Computer Rights" to modify user permissions. Next select “Other Rights” and modify accordingly.
- RMF Control
- AU-9
- Severity
- M
- CCI
- CCI-001348
- Version
- TMDS-00-000120
- Vuln IDs
-
- V-241130
- V-65899
- Rule IDs
-
- SV-241130r879582_rule
- SV-80389
Checks: C-44363r678613_chk
Review the Trend Deep Security server configuration to ensure audit records are backed up at least every seven days onto a different system or system component than the system or component being audited. Verify the application backup frequency by reviewing the configuration settings in Administration >> System Settings >> SIEM If the "Forward System Events to a remote computer (via Syslog)" is not enabled with the proper configuration settings, this is a finding.
Fix: F-44322r678614_fix
Configure the Trend Deep Security server to back up audit records at least every seven days onto a different system or system component than the system or component being audited. Configure the application to forward audit records to a log management tool for backup and storage. Go to Administration >> System Settings >> SIEM Enable "Forward System Events to a remote computer (via Syslog)" Configure the following: Hostname or IP address to which events should be sent UDP port to which events should be sent Syslog Facility Syslog Format
- RMF Control
- AU-9
- Severity
- H
- CCI
- CCI-001350
- Version
- TMDS-00-000125
- Vuln IDs
-
- V-241131
- V-65901
- Rule IDs
-
- SV-241131r879583_rule
- SV-80391
Checks: C-44364r678616_chk
Review the Trend Deep Security server configuration to ensure cryptographic mechanisms are used to protect the integrity of audit information. Verify PDF encryption is enabled for report generation. Go to Administration >> User Management >> Users >> Right-click an administrative user account and select "Properties". Within the "Settings" tab select "Enable PDF Encryption". If "Enable PDF Encryption" is not enabled, this is a finding.
Fix: F-44323r678617_fix
Configure the Trend Deep Security server to use cryptographic mechanisms to protect the integrity of audit information. Enabled encryption for report generation. Go to Administration >> User Management >> Users >> Right-click an administrative user account and select "Properties". Within the "Settings" tab select "Enable PDF Encryption" and enter a password.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000382
- Version
- TMDS-00-000130
- Vuln IDs
-
- V-241132
- V-65903
- Rule IDs
-
- SV-241132r879588_rule
- SV-80393
Checks: C-44365r678619_chk
Review the Trend Deep Security server to ensure the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments, are prohibited or restricted. Review the firewall policy for approved ports, protocols and services associated within a defined group or a selected computer by selecting Computers, on the top menu bar. Choose the appropriate group and within the main page, select a computer for review. Double-click the selected computer and click "Firewall". Verify the following settings are enabled: Configuration: Inherit or On State: Activated Firewall Stateful Configurations: Inherited (If managed through a group policy) Assigned Firewall Rules: (are configured in accordance with local security policy) If the options identified are not set or configured in accordance with local policy, this is a finding.
Fix: F-44324r678620_fix
Configure the Trend Deep Security server to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments. From the top menu select Policies >> New >> New Policy. Enter a Name for the new policy; In Inherit from, select “None”. Click “Next” and Select “Yes”. Choose the applicable computers that will inherit this policy, and click “Next”. Ensure all options are selected from the “Select which Computer properties to base new Policy on:” window, and click “Next”. Click “Finish”.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- TMDS-00-000135
- Vuln IDs
-
- V-241133
- V-65909
- Rule IDs
-
- SV-241133r879589_rule
- SV-80399
Checks: C-44366r678622_chk
Review the Trend Deep Security server configuration to ensure organizational users (or processes acting on behalf of organizational users) are uniquely identified and authenticated. Verify the user accounts under Administration >> User Management >> Users If the accounts configured do not uniquely specify the organizational user's affiliation, this is a finding.
Fix: F-44325r678623_fix
Configure the Trend Deep Security server to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). Configure the appropriate affiliation display for the specified user under Administration >> User Management >> Users Right click the user account. Click "Properties" and Select “User Name”. Enter the appropriate user identifiers.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000205
- Version
- TMDS-00-000140
- Vuln IDs
-
- V-241134
- V-65915
- Rule IDs
-
- SV-241134r879601_rule
- SV-80405
Checks: C-44367r678625_chk
Review the Trend Deep Security server configuration to ensure a minimum 15-character password length is enforced. Verify the policy value for minimum password length. If the value for “User password minimum length” under the Administration >> System Settings >> Security tab is not set to 15, this is a finding.
Fix: F-44326r678626_fix
Configure the Trend Deep Security server to enforce a minimum 15-character password length. Configure the policy value for minimum password length. Under the Administration >> System Settings >> Security tab, set the value for “User password minimum length” to 15.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000192
- Version
- TMDS-00-000145
- Vuln IDs
-
- V-241135
- V-65917
- Rule IDs
-
- SV-241135r879603_rule
- SV-80407
Checks: C-44368r678628_chk
Review the Trend Deep Security server configuration to ensure password complexity is enforced by requiring that at least one upper-case character be used. Verify the values for password complexity. If the "User password requires both upper-and lower-case characters" value for password complexity under the Administration >> System Settings >> Security tab has not been set, this is a finding.
Fix: F-44327r678629_fix
Configure the Trend Deep Security server to enforce password complexity by requiring that at least one uppercase character be used. Enable the checkbox for the "User password requires both upper-and lower-case characters" policy value for password complexity under the Administration >> System Settings >> Security tab.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000193
- Version
- TMDS-00-000150
- Vuln IDs
-
- V-241136
- V-66047
- Rule IDs
-
- SV-241136r879604_rule
- SV-80537
Checks: C-44369r678631_chk
Review the Trend Deep Security server configuration to ensure password complexity is enforced by requiring that at least one lower-case character be used. Verify the values for password complexity. If the "User password requires both upper-and lower-case characters" value for password complexity under the Administration >> System Settings >> Security tab has not been set, this is a finding.
Fix: F-44328r678632_fix
Configure the Trend Deep Security server to enforce password complexity by requiring that at least one lower-case character be used. Enable the checkbox for the "User password requires both upper-and lower-case characters" policy value for password complexity under the Administration >> System Settings >> Security tab.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000194
- Version
- TMDS-00-000155
- Vuln IDs
-
- V-241137
- V-65919
- Rule IDs
-
- SV-241137r879605_rule
- SV-80409
Checks: C-44370r678634_chk
Review the Trend Deep Security server configuration to ensure password complexity is enforced by requiring that at least one numeric character be used. Verify the values for password complexity. If the "User password requires both letters and numbers" value for password complexity under the Administration >> System Settings >> Security tab has not been set, this is a finding.
Fix: F-44329r678635_fix
Configure the Trend Deep Security server to enforce password complexity by requiring that at least one numeric character be used. Enable the checkbox for the "User password requires both letters and numbers" policy value for password complexity under the Administration >> System Settings >> Security tab.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-001619
- Version
- TMDS-00-000160
- Vuln IDs
-
- V-241138
- V-65921
- Rule IDs
-
- SV-241138r879606_rule
- SV-80411
Checks: C-44371r678637_chk
Review the Trend Deep Security server configuration to ensure password complexity is enforced by requiring that at least one special character be used. Verify the values for password complexity. If the "User password requires non-alphanumeric characters" value for password complexity under the Administration >> System Settings >> Security tab has not been set, this is a finding.
Fix: F-44330r678638_fix
Configure the Trend Deep Security server to enforce password complexity by requiring that at least one special character be used. Enable the checkbox for the "User password requires non-alphanumeric characters" policy value for password complexity under the Administration >> System Settings >> Security tab.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000199
- Version
- TMDS-00-000165
- Vuln IDs
-
- V-241139
- V-65925
- Rule IDs
-
- SV-241139r879611_rule
- SV-80415
Checks: C-44372r678640_chk
Review the Trend Deep Security server configuration to ensure a 60 day maximum password lifetime restriction is enforced. Verify the policy value for minimum password length. If the value for “User password expires” under the Administration >> System Settings >> Security tab is not set to 60 Days, this is a finding.
Fix: F-44331r678641_fix
Configure the Trend Deep Security server to enforce a 60 day maximum password lifetime restriction. Configure the policy value for maximum password lifetime. Under the Administration >> System Settings >> Security tab, set the value for “User password expires” to 60.
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-000804
- Version
- TMDS-00-000170
- Vuln IDs
-
- V-241140
- V-65927
- Rule IDs
-
- SV-241140r879617_rule
- SV-80417
Checks: C-44373r678643_chk
Review the Trend Deep Security server configuration to ensure non-organizational users (or processes acting on behalf of non-organizational users) are uniquely identified and authenticated. Verify the user accounts under Administration >> User Management >> Users If the accounts configured do not uniquely specify the organizational user's affiliation, this is a finding.
Fix: F-44332r678644_fix
Configure the Trend Deep Security server to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users). To help prevent inadvertent disclosure of controlled information, all contractors are identified by the inclusion of the abbreviation "ctr" and all foreign nationals are identified by the inclusion of their two character country code. See ECAD-1 Affiliation Display Configure the appropriate affiliation display for the specified user under Administration >> User Management >> Users Right click the user account. Click "Properties" and Select “User Name”. Enter the appropriate user identifiers.
- RMF Control
- SC-10
- Severity
- M
- CCI
- CCI-001133
- Version
- TMDS-00-000175
- Vuln IDs
-
- V-241141
- V-65929
- Rule IDs
-
- SV-241141r879622_rule
- SV-80419
Checks: C-44374r678646_chk
Review the Trend Deep Security server configuration to ensure all network connections associated with a communications session are terminated at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity; and for user sessions (non-privileged session), the session must be terminated after 15 minutes of inactivity, except to fulfill documented and validated mission requirements. If the value for user session termination under the Administration >> System Settings >> Security >> Session timeout, is not set to 10 minutes, this is a finding.
Fix: F-44333r678647_fix
Configure the Trend Deep Security server to terminate all network connections associated with a communications session at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity; and for user sessions (non-privileged session), the session must be terminated after 15 minutes of inactivity, except to fulfill documented and validated mission requirements. Configure the policy value for session timeout. Under the Administration >> System Settings >> Security, set the value for “Session timeout” to 10 minutes.
- RMF Control
- SC-3
- Severity
- M
- CCI
- CCI-001084
- Version
- TMDS-00-000180
- Vuln IDs
-
- V-241142
- V-65931
- Rule IDs
-
- SV-241142r879643_rule
- SV-80421
Checks: C-44375r678649_chk
Review the Trend Deep Security server configuration to ensure security functions are isolated from non-security functions. In order to restrict access to security functions through the use of access control mechanisms, least privilege capabilities must be enforced within the Deep Security, “User management” settings. If role-based access controls are not enforced within the Administration >> User management >> Roles, this is a finding.
Fix: F-44334r678650_fix
Configure the Trend Deep Security server to isolate security functions from non-security functions. Configure role-based access controls for least privileged accounts within the Administration >> User management >> Roles.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001094
- Version
- TMDS-00-000185
- Vuln IDs
-
- V-241143
- V-65933
- Rule IDs
-
- SV-241143r879650_rule
- SV-80423
Checks: C-44376r678652_chk
Review the Trend Deep Security server configuration to ensure the ability of individuals to use information systems to launch organization-defined Denial of Service (DoS) attacks against other information systems is restricted. Deep Security policies for Firewall Rules can be disruptive causing a denial of service to the environment if not properly configured. It is imperative that access to the firewall rule policies be restricted to authorized personnel by enforcing least privileged within the Deep Security, “User management” settings. If role-based access controls are not enforced within the Administration >> User management >> Roles >> [Policy Name] >> Properties >> Policy Rights, this is a finding.
Fix: F-44335r678653_fix
Configure the Trend Deep Security server to restrict the ability of individuals to use information systems to launch organization-defined Denial of Service (DoS) attacks against other information systems. Configure the role-based access controls to prevent access to policy modifications within the Administration >> User management >> Roles >> [Policy Name] >> Properties >> Policy Rights. The “Edit” option should only be enabled to authorized users.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001095
- Version
- TMDS-00-000190
- Vuln IDs
-
- V-241144
- V-65935
- Rule IDs
-
- SV-241144r879651_rule
- SV-80425
Checks: C-44377r678655_chk
Review the Trend Deep Security server configuration to ensure excess capacity, bandwidth, or other redundancy is managed to limit the effects of information flooding types of Denial of Service (DoS) attacks. Review the “CPU Usage Level” under Administration >> System Settings >> Advanced >> CPU Usage During Recommendation Scans. Depending on resource capabilities for monitored agent scans, it may be necessary to limit the “CPU Usage Level” from High to Low. If the setting is not configured in accordance with the SA best practice recommendation this is a finding.
Fix: F-44336r678656_fix
Configure the Trend Deep Security server to manage excess capacity, bandwidth, or other redundancy to limit the effects of information flooding types of Denial of Service (DoS) attacks. Configure the “CPU Usage Level” in accordance with the SA best practice under Administration >> System Settings >> Advanced >> CPU Usage During Recommendation Scans.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001247
- Version
- TMDS-00-000195
- Vuln IDs
-
- V-241145
- V-65937
- Rule IDs
-
- SV-241145r879659_rule
- SV-80427
Checks: C-44378r678658_chk
Review the Trend Deep Security server configuration to ensure malicious code protection mechanisms are automatically updated. Analyze the system using the Administration >> System Settings >> Updates page. Verify that the “Automatically download updates to imported software” option is checked. If this option is not enabled, this is a finding.
Fix: F-44337r678659_fix
Configure the Trend Deep Security server to automatically update malicious code protection mechanisms. Go to the Administration >> System Settings >> Updates page, and scroll down to Software Updates. Check the box to enable “Automatically download updates to imported software”.
- RMF Control
- SI-6
- Severity
- M
- CCI
- CCI-001294
- Version
- TMDS-00-000200
- Vuln IDs
-
- V-241146
- V-65939
- Rule IDs
-
- SV-241146r879661_rule
- SV-80429
Checks: C-44379r678661_chk
Review the Trend Deep Security server configuration to ensure the ISSO and ISSM are notified of failed security verification tests. From Administration >> User Management >> Users Select the account associated with the ISSM or ISSO and double-click. Under the Contact Information tab, verify the Contact Information is associated with account is complete and accurate. If the account information is missing or incorrect, this is a finding. Next, verify the "Receive Alert Email" check box is selected. If the "Receive Alert Email" checkbox is not selected, this is finding.
Fix: F-44338r678662_fix
Configure the Trend Deep Security server to notify ISSO and ISSM of failed security verification tests. Go to Administration >> User Management >> Users Select the account associated with the ISSM or ISSO and double-click. Under the “Contact Information” tab enter the users Contact Information. Next, select the checkbox for “Receive Alert Emails”.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001240
- Version
- TMDS-00-000205
- Vuln IDs
-
- V-241147
- V-65941
- Rule IDs
-
- SV-241147r879662_rule
- SV-80431
Checks: C-44380r678664_chk
Review the Trend Deep Security server configuration to ensure malicious code protection mechanisms are updated whenever new releases are available in accordance with organizational configuration management policy and procedures. Analyze the system using the Administration >> System Settings >> Updates page. Verify that the “Automatically download updates to imported software” option is enabled. If this option is not enabled, this is a finding.
Fix: F-44339r678665_fix
Configure the Trend Deep Security server to update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy and procedures. Go to the Administration >> System Settings >> Updates page, and scroll down to Software Updates. Check the box to enable “Automatically download updates to imported software”.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001241
- Version
- TMDS-00-000210
- Vuln IDs
-
- V-241148
- V-65943
- Rule IDs
-
- SV-241148r879663_rule
- SV-80433
Checks: C-44381r678667_chk
Review the Trend Deep Security server configuration to ensure malicious code protection mechanisms perform periodic scans of the information system every seven (7) days. Analyze one of the custom policies under the “Policies” tab, by right clicking and selecting “Details.” Verify the following settings are enabled: 1. Under the Overview >> General tab, "Anti-Malware" is set to “On” 2. Under the Anti-Malware >> General tab, “Real-Time Scan” is set to “Default” 3. Under the Anti-Malware >> General tab, a custom “Malware Scan Configuration” is enabled with a Schedule configured to no more than 7 days. If "Anti-Malware" is set anything other than “On” this is a finding. If “Malware Scan Configuration” is set to “No Configuration,” this is a finding.
Fix: F-44340r678668_fix
Configure the Trend Deep Security server malicious code protection mechanisms to perform periodic scans of the information system every seven (7) days. To enable malicious code protection via the anti-malware, configure the following settings under the “Policies” tab. Under “Policies” right clicking and selecting “Details.” Configure the following settings: 1. Under the Overview >> General tab, set "Anti-Malware" to “On” 2. Under the Anti-Malware >> General tab, set “Real-Time Scan” to “Default” 3. Under the Anti-Malware >> General tab, set a weekly scan under “Scheduled” by selecting “New”. Name the scheduled scan “Weekly” and configure it for a select day and time of the week. Click “OK” when finished.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001242
- Version
- TMDS-00-000215
- Vuln IDs
-
- V-241149
- V-65945
- Rule IDs
-
- SV-241149r879664_rule
- SV-80435
Checks: C-44382r678670_chk
Review the Trend Deep Security server to ensure real-time malicious code protection scans are performed on files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy. Verify the Anti-Malware, Real-Time Scan is enabled by reviewing the following settings under the “Policies” tab. Under “Policies” right click and select “Details” and choose “Anti-Malware. Review the following settings: Anti-Malware State is set to “On” and the “Real-Time Scan” is set to “Default.” If the two settings are not configured accordingly, this is a finding.
Fix: F-44341r678671_fix
Configure the Trend Deep Security server to perform real-time malicious code protection scans of files from external sources at endpoints as the files are downloaded, opened, or executed in accordance with organizational security policy. To enable malicious code protection via the anti-malware, configure the following settings under the “Policies” tab. Under “Policies” right clicking and selecting “Details.” Configure the following settings: 1. Under the Overview >> General tab, set "Anti-Malware" to “On” 2. Under the Anti-Malware >> General tab, set “Real-Time Scan” to “Default”. Click “OK” when finished.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- TMDS-00-000220
- Vuln IDs
-
- V-241150
- V-65947
- Rule IDs
-
- SV-241150r879665_rule
- SV-80437
Checks: C-44383r678673_chk
Review the Trend Deep Security server configuration to ensure malicious code is blocked and quarantined upon detection, then send an immediate alert to appropriate individuals. Verify the “Custom remediation actions” for “Recognized Malware” under the Policy settings for Anti-Malware. - Under “Policies” tab right click any of the selected policies and click “Details.” - Choose “Anti-Malware” and deselect “Default Real-Time Scan Configuration.” Be sure to re-enable this option once the review is complete. - Click “Edit” and select “Actions.” - Under the “Recognized Malware” verify the following settings: - For Virus: Clean - For Trojans: Quarantine - For Packer: Quarantine - For Spyware: Quarantine - For Other Threats: Clean - Under “Possible Malware” verify “Quarantine” is selected. If any of the settings are not configured accordingly, this is a finding.
Fix: F-44342r678674_fix
Configure the Trend Deep Security server to block and quarantine malicious code upon detection, then send an immediate alert to appropriate individuals. Configure the “Custom remediation actions” for “Recognized Malware” under the Policy settings for Anti-Malware. - Under “Policies” tab right click any of the selected policies and click “Details.” - Choose “Anti-Malware” and deselect “Default Real-Time Scan Configuration.” Be sure to re-enable this option once the review is complete. - Click “Edit” and select “Actions.” - Under the “Recognized Malware” configure the following settings: - For Virus: Clean - For Trojans: Quarantine - For Packer: Quarantine - For Spyware: Quarantine - For Other Threats: Clean - Under “Possible Malware” select “Quarantine.”
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001683
- Version
- TMDS-00-000225
- Vuln IDs
-
- V-241151
- V-65949
- Rule IDs
-
- SV-241151r879669_rule
- SV-80439
Checks: C-44384r678676_chk
Review the Trend Deep Security server configuration to ensure System Administrators and Information System Security Officers are notified when accounts are created. 1. Analyze the system using the Administration >> System Settings >> Alerts. Review the email address listed in the “Alert Event Forwarding (From The Manager).” If this email address is not present or does not belong to a distribution for system administrators and ISSOs, this is a finding. 2. Analyze the system using the Administration >> System Settings >> System Events for “User Created” Event ID 650. If the options for “Record” and “Forward” are not enabled for "User Created", this is a finding.
Fix: F-44343r678677_fix
Configure the Trend Deep Security server to notify System Administrators and Information System Security Officers when accounts are created. 1. Configure Events and Alerts to notify the SA and ISSO using the Administration >> System Settings >> Alerts tab. Inset a distribution email address into the “Alert Event Forwarding (From The Manager).” The distribution email address must be configured within Exchange or other email server and must associate the SA and ISSO accounts reviewing and/or managing the system. 2. Configure the alert using the Administration >> System Settings >> System Events for “User Created” Event ID 650. Select the options for “Record and Forward”.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001684
- Version
- TMDS-00-000230
- Vuln IDs
-
- V-241152
- V-65951
- Rule IDs
-
- SV-241152r879670_rule
- SV-80441
Checks: C-44385r678679_chk
Review the Trend Deep Security server configuration to ensure System Administrators and Information System Security Officers are notified when accounts are modified. 1. Analyze the system using the Administration >> System Settings >> Alerts. Review the email address listed in the “Alert Event Forwarding (From The Manager).” If this email address is not present or does not belong to a distribution for system administrators and ISSOs, this is a finding. 2. Analyze the system using the Administration >> System Settings >> System Events for “User Updated” Event ID 652. If the options for “Record” and “Forward” are not enabled for "User Updated", this is a finding.
Fix: F-44344r678680_fix
Configure the Trend Deep Security server to notify System Administrators and Information System Security Officers when accounts are modified. 1. Configure Events and Alerts to notify the SA and ISSO using the Administration > System Settings > Alerts tab. Inset a distribution email address into the “Alert Event Forwarding (From The Manager).” The distribution email address must be configured within Exchange or other email server and must associate the SA and ISSO accounts reviewing and/or managing the system. 2. Configure the alert using the Administration > System Settings > System Events for “User Updated” Event ID 652. Select the options for Record and Forward.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001685
- Version
- TMDS-00-000235
- Vuln IDs
-
- V-241153
- V-65953
- Rule IDs
-
- SV-241153r879671_rule
- SV-80443
Checks: C-44386r678682_chk
Review the Trend Deep Security server configuration to ensure System Administrators and Information System Security Officers are notified when accounts are disabled. 1. Analyze the system using the Administration >> System Settings >> Alerts. Review the email address listed in the “Alert Event Forwarding (From The Manager).” If this email address is not present or does not belong to a distribution for system administrators and ISSOs, this is a finding. 2. Analyze the system using the Administration >> System Settings >> System Events for “User Locked Out” Event ID 603. If the options for “Record” and “Forward” are not enabled for "User Locked Out", this is a finding.
Fix: F-44345r678683_fix
Configure the Trend Deep Security server to notify System Administrators and Information System Security Officers for account disabling actions. 1. Configure Events and Alerts to notify the SA and ISSO using the Administration >> System Settings >> Alerts tab. Inset a distribution email address into the “Alert Event Forwarding (From The Manager).” The distribution email address must be configured within Exchange or other email server and must associate the SA and ISSO accounts reviewing and/or managing the system. 2. Configure the alert using the Administration >> System Settings >> System Events for “User Locked Out” Event ID 603. Select the options for “Record” and “Forward”.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-001686
- Version
- TMDS-00-000240
- Vuln IDs
-
- V-241154
- V-65955
- Rule IDs
-
- SV-241154r879672_rule
- SV-80445
Checks: C-44387r678685_chk
Review the Trend Deep Security server configuration to ensure System Administrators and Information System Security Officers are notified when accounts are removed. 1. Analyze the system using the Administration >> System Settings >> Alerts. Review the email address listed in the “Alert Event Forwarding (From The Manager).” If this email address is not present or does not belong to a distribution for system administrators and ISSOs, this is a finding. 2. Analyze the system using the Administration >> System Settings >> System Events for “User Deleted” Event ID 651. If the options for “Record” and “Forward” are not enabled for "User Deleted", this is a finding.
Fix: F-44346r678686_fix
Configure the Trend Deep Security server to notify System Administrators and Information System Security Officers for account removal actions. 1. Configure Events and Alerts to notify the SA and ISSO using the Administration >> System Settings >> Alerts tab. Inset a distribution email address into the “Alert Event Forwarding (From The Manager).” The distribution email address must be configured within Exchange or other email server and must associate the SA and ISSO accounts reviewing and/or managing the system. 2. Configure the alert using the Administration >> System Settings >> System Events for “User Deleted” Event ID 651. Select the options for “Record” and “Forward”.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-002130
- Version
- TMDS-00-000245
- Vuln IDs
-
- V-241155
- V-65957
- Rule IDs
-
- SV-241155r879696_rule
- SV-80447
Checks: C-44388r678688_chk
Review the Trend Deep Security server configuration to ensure account enabling actions are automatically audited. 1. Analyze the system using the Administration >> System Settings >> Alerts. Review the email address listed in the “Alert Event Forwarding (From The Manager).” If this email address is not present or does not belong to a distribution for system administrators and ISSOs, this is a finding. 2. Analyze the system using the Administration >> System Settings >> System Events for “User Created” Event ID 650. If the options for “Record” and “Forward” are not enabled for "User Created", this is a finding.
Fix: F-44347r678689_fix
Configure the Trend Deep Security server to automatically audit account enabling actions. 1. Configure Events and Alerts to notify the SA and ISSO using the Administration >> System Settings >> Alerts tab. Inset a distribution email address into the “Alert Event Forwarding (From The Manager).” The distribution email address must be configured within Exchange or other email server and must associate the SA and ISSO accounts reviewing and/or managing the system. 2. Configure the alert using the Administration >> System Settings >> System Events for “User Created” Event ID 650. Select the options for “Record” and “Forward”.
- RMF Control
- AC-2
- Severity
- M
- CCI
- CCI-002132
- Version
- TMDS-00-000250
- Vuln IDs
-
- V-241156
- V-65959
- Rule IDs
-
- SV-241156r879697_rule
- SV-80449
Checks: C-44389r678691_chk
Review the Trend Deep Security server configuration to ensure the SA and ISSO are notified of account enabling actions. 1. Analyze the system using the Administration >> System Settings >> Alerts. Review the email address listed in the “Alert Event Forwarding (From The Manager).” If this email address is not present or does not belong to a distribution for system administrators and ISSOs, this is a finding. 2. Analyze the system using the Administration >> System Settings >> System Events for “User Created” Event ID 650. If the options for “Record” and “Forward” are not enabled for "User Created", this is a finding.
Fix: F-44348r678692_fix
Configure the Trend Deep Security server to notify SA and ISSO of account enabling actions. 1. Configure Events and Alerts to notify the SA and ISSO using the Administration >> System Settings >> Alerts tab. Inset a distribution email address into the “Alert Event Forwarding (From The Manager).” The distribution email address must be configured within Exchange or other email server and must associate the SA and ISSO accounts reviewing and/or managing the system. 2. Configure the alert using the Administration >> System Settings >> System Events for “User Created” Event ID 650. Select the options for “Record” and “Forward”.
- RMF Control
- AC-6
- Severity
- M
- CCI
- CCI-002234
- Version
- TMDS-00-000255
- Vuln IDs
-
- V-241157
- V-65967
- Rule IDs
-
- SV-241157r879720_rule
- SV-80457
Checks: C-44390r678694_chk
Review the Trend Deep Security server to ensure the execution of privileged functions are audited. Interview the ISSO for a list of functions identified as privileged within the application “System Events.” Privileged functions within the system events will include but are not limited to: Computer Created, Computer Deleted, User Added, etc.). Verify the list against the Administration >> System Settings >> System Events tab. If the events are not to Record and Forward, this is a finding.
Fix: F-44349r678695_fix
Configure the Trend Deep Security server to audit the execution of privileged functions. Enable the necessary privileged functions by selecting “Record” and “Forward” within the Administration >> System Settings >> System Events tab.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- TMDS-00-000265
- Vuln IDs
-
- V-241158
- V-65969
- Rule IDs
-
- SV-241158r879731_rule
- SV-80459
Checks: C-44391r678697_chk
Review the Trend Deep Security server configuration to ensure audit records are off-loaded onto a different system or media than the system being audited. Verify that audit records are off-loaded by configuring the Manager to instruct all managed computers to use Syslog: 1. Go to the Administration> > System Settings >> SIEM tab. 2. In the System Event Notification (from the Manager) area, verify the “Forward System Events to a remote computer (via Syslog) option” is Enabled. 3. Verify the IP address to the selected host name is entered. 4. Verify UDP port 514 or agency selected port is provided. 5. Verify the appropriate Syslog facility and Common Event Settings If any of these settings are missing from the SIEM configuration, this is a finding.
Fix: F-44350r678698_fix
Configure the Trend Deep Security server to off-load audit records onto a different system or media than the system being audited. To configure the Manager to instruct all managed computers to use Syslog: 1. Go to the Administration >> System Settings >> SIEM tab. 2. In the System Event Notification (from the Manager) area, set the Forward System Events to a remote computer (via Syslog) option. 3. Type the hostname or the IP address of the Syslog computer. 4. Enter which UDP port to use (usually 514). 5. Select which Syslog facility to use. 6. Select the "Common Event Format" log format. (The "Basic Syslog" format is listed only for legacy support and should not be used for new integrations.)
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-001855
- Version
- TMDS-00-000270
- Vuln IDs
-
- V-241159
- V-65971
- Rule IDs
-
- SV-241159r879732_rule
- SV-80461
Checks: C-44392r678700_chk
Review the Trend Deep Security server configuration to ensure an immediate warning is provided to the SA and ISSO (at a minimum) when allocated audit record storage volume reaches 75% of repository maximum audit record storage capacity. 1. Analyze the system using the Administration > System Settings >> Alerts tab. Review the email address listed in the “Alert Event Forwarding (From The Manager).” If this email address is not present or does not belong to a distribution for system administrator and ISSOs, this is a finding. 2. Analyze the system using the Administration >> System Settings >> System Events tab for “Manager Available Disk Space Too Low” Event ID 170. If the options for “Record” and “Forward” are not enabled for “Manager Available Disk Space Too Low”, this is a finding
Fix: F-44351r678701_fix
Configure the Trend Deep Security server to provide an immediate warning to the SA and ISSO (at a minimum) when allocated audit record storage volume reaches 75% of repository maximum audit record storage capacity. 1. Configure Events and Alerts to notify the SA and ISSO using the Administration >> System Settings >> Alerts tab. Inset a distribution email address into the “Alert Event Forwarding (From The Manager).” The distribution email address must be configured within Exchange or other email server and must associate the SA and ISSO accounts reviewing and/or managing the system. 2. Configure the alert using the Administration >> System Settings >> System Events for “Manager Available Disk Space Too Low” Event ID 170. Select the options for “Record” and “Forward”.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-001858
- Version
- TMDS-00-000275
- Vuln IDs
-
- V-241160
- V-65973
- Rule IDs
-
- SV-241160r879733_rule
- SV-80463
Checks: C-44393r678703_chk
Review the Trend Deep Security server configuration to ensure an immediate real-time alert is provided to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts. Analyze the system using the Administration >> System Settings >> Alerts tab. Review the email address listed in the “Alert Event Forwarding (From The Manager).” If this email address is not present or does not belong to a distribution for system administrators and ISSOs, this is a finding.
Fix: F-44352r678704_fix
Configure the Trend Deep Security server to provide an immediate real-time alert to the SA and ISSO, at a minimum, of all audit failure events requiring real-time alerts. Configure Events and Alerts to notify the SA and ISSO using the Administration >> System Settings >> Alerts tab. Insert a distribution email address into the “Alert Event Forwarding (From The Manager).” The distribution email address must be configured within Exchange or other email server and must associate the SA and ISSO accounts reviewing and/or managing the system.
- RMF Control
- CM-11
- Severity
- M
- CCI
- CCI-001811
- Version
- TMDS-00-000280
- Vuln IDs
-
- V-241161
- V-65975
- Rule IDs
-
- SV-241161r879750_rule
- SV-80465
Checks: C-44394r678706_chk
Review the Trend Deep Security server configuration to ensure the ISSO, ISSM, and other designated personnel (deemed appropriate by the local organization) are alerted when the unauthorized installation of software is detected. 1. Analyze the system using the Administration >> System Settings >> Alerts tab. Review the email address listed in the “Alert Event Forwarding (From The Manager).” If this email address is not present or does not belong to a distribution for system administrators and ISSOs, this is a finding. 2. Analyze the system using the Administration >> System Settings >> System Events for “Software Added” Event ID 151. If the options for “Record” and “Forward” are not enabled for “Software Added”, this is a finding.
Fix: F-44353r678707_fix
Configure the Trend Deep Security server to alert the ISSO, ISSM, and other designated personnel (deemed appropriate by the local organization) when the unauthorized installation of software is detected. 1. Configure Events and Alerts to notify the SA and ISSO using the Administration >> System Settings >> Alerts tab. Inset a distribution email address into the “Alert Event Forwarding (From The Manager).” The distribution email address must be configured within Exchange or other email server and must associate the SA and ISSO accounts reviewing and/or managing the system. 2. Configure the alert using the Administration >> System Settings >> System Events for “Software Added” Event ID 151. Select the options for “Record” and “Forward”.
- RMF Control
- CM-11
- Severity
- M
- CCI
- CCI-001812
- Version
- TMDS-00-000285
- Vuln IDs
-
- V-241162
- V-65977
- Rule IDs
-
- SV-241162r879751_rule
- SV-80467
Checks: C-44395r678709_chk
Review the Trend Deep Security server configuration to ensure user installation of software without explicit privileged status is prohibited. Analyze the system using Administration >> User Management >> Roles. Review each role created that is not “Full Access”. Right-Click >> Properties on the desired role, and select “Other Rights.” The “Updates” setting should be set to “View Only” or “Hide.” If any other option is selected other than “View Only” or “Hide”, this is a finding.
Fix: F-44354r678710_fix
Configure the Trend Deep Security server to prohibit user installation of software without explicit privileged status. Configure the application to prevent non-authorized users from updating Deep Security by selecting Administration >> User Management >> Roles. Right-Click >> Properties on any of the roles listed and choose “Other Rights.” Set the “Updates” setting to “View Only” or “Hide”.
- RMF Control
- CM-3
- Severity
- M
- CCI
- CCI-001744
- Version
- TMDS-00-000290
- Vuln IDs
-
- V-241163
- V-65979
- Rule IDs
-
- SV-241163r879752_rule
- SV-80469
Checks: C-44396r678712_chk
Review the Trend Deep Security server configuration to ensure organization-defined automated security responses are implemented if baseline configurations are changed in an unauthorized manner. Deep Security, Policies, are policy templates that specify the security rules to be configured and enforced automatically for one or more computers. These compact, manageable rule sets make it simple to provide comprehensive security without the need to manage thousands of rules. Default Policies provide the necessary rules for a wide range of common computer configurations. 1. Analyze the system using the Administration >> System Settings >> Alerts tab. Review the email address listed in the “Alert Event Forwarding (From The Manager).” If this email address is not present or does not belong to a distribution for system administrator and ISSOs, this is a finding. 2. Analyze the system using the Administration >> System Settings >> System Events tab to ensure the following events are enabled: 350 Policy Created Record Forward 351 Policy Deleted Record Forward 352 Policy Updated Record Forward 353 Policies Exported Record Forward 354 Policies Imported Record Forward If the options for “Record” and “Forward” are not enabled on these events, this is a finding
Fix: F-44355r678713_fix
Configure the Trend Deep Security server to implement organization-defined automated security responses if baseline configurations are changed in an unauthorized manner. Configure the application to prevent unauthorized changes to the baseline policies by selecting Administration >> System Settings >> System Events. Enable the Record and Forward option for each of the following: 350 Policy Created 351 Policy Deleted 352 Policy Updated 353 Policies Exported 354 Policies Imported
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001813
- Version
- TMDS-00-000295
- Vuln IDs
-
- V-241164
- V-65981
- Rule IDs
-
- SV-241164r879753_rule
- SV-80471
Checks: C-44397r678715_chk
Review the Trend Deep Security server configuration to ensure access restrictions associated with changes to application configuration are enforced. Inspect the settings used for enforcing least privilege through access restrictions under Administration >> User Management >> Roles. Select a role under the “Roles” menu and click "Properties". 1. Select the “Computer Rights” tab and verify the settings configured under the “Computer and Group Rights” area. If non-authorized users have access to anything other than “View”, this is a finding. 2. Select the “Policy Rights” tab and verify the settings configured under the “Policy Rights” area. If non-authorized users have access to anything other than “View,” this is a finding. 3. Select the “User Rights” tab and verify the settings configured under the “User Rights” area. If non-authorized users have access to anything other than “Change own password and contact information only”, this is a finding. 4. Select the Other Rights, tab and verify the settings configured under the “Other Rights” area. If non-authorized users have access to anything other than "View-Only" or "Hide", this is a finding.
Fix: F-44356r678716_fix
Configure the Trend Deep Security server to enforce access restrictions associated with changes to application configuration. Enforce access restrictions associated with changes to application configuration. Under Administration >> User Management >> Roles, select a role and click “Properties”. 1. Click Computer Rights >> Computer and Group Rights, and select only the “View” checkbox. 2. Click Policy Rights >> Policy Rights, and select only the “View” checkbox. 3. Click User Rights >> User Rights, and select “Change own password and contact information only.” 4. Click Other Rights >> Other Rights, select "View-Only" or "Hide" for all options according to local policy for the roles permission. 5. Click "OK".
- RMF Control
- CM-5
- Severity
- M
- CCI
- CCI-001814
- Version
- TMDS-00-000300
- Vuln IDs
-
- V-241165
- V-65983
- Rule IDs
-
- SV-241165r879754_rule
- SV-80473
Checks: C-44398r678718_chk
Review the Trend Deep Security server configuration to ensure the enforcement actions used to restrict access associated with changes to the application are audited. System Events include changes to the configuration of an Agent/Appliance, the Deep Security Manager, or Users. They also include errors that may occur during normal operation of the Trend Deep Security system. To ensure the necessary events are captured, verify the Administration >> System Settings >> System Events, against the local policy established by the ISSO. If the settings configured do not match local policy, this is a finding.
Fix: F-44357r678719_fix
Configure the Trend Deep Security server to audit the enforcement actions used to restrict access associated with changes to the application. To configure the application to captured the events identified by the ISSO, go to the Administration >> System Settings >> System Events tab. Enable all applicable policies with “Record” and “Forward.”
- RMF Control
- SC-23
- Severity
- M
- CCI
- CCI-002470
- Version
- TMDS-00-000305
- Vuln IDs
-
- V-241166
- V-65985
- Rule IDs
-
- SV-241166r879798_rule
- SV-80475
Checks: C-44399r678721_chk
Review the Trend Deep Security server configuration to ensure only the use of DoD PKI established certificate authorities are allowed for verification of the establishment of protected sessions. Verify the certificate CA and by reviewing the issued to and validity date by clicking the certificate icon in the web browser and selecting View Certificates, Certificate Information, etc. (browser dependent). If the certificate is not issued by a DoD CA, this is a finding.
Fix: F-44358r678722_fix
Configure the Trend Deep Security server to only allow the use of DoD PKI established certificate authorities for verification of the establishment of protected sessions. 1. Run the following command to create a CSR for your CA to sign: C:\Program Files\Trend Micro\Deep Security Manager\jre\bin>keytool -certreq -keyalg RSA -alias tomcat -file certrequest.csr 2. Send the certrequest.csr to your CA to sign. In return you will get two files. One is a "certificate reply" and the second is the CA certificate itself. 3. Run the following command to import the CA cert in JAVA trusted keystore: C:\Program Files\Trend Micro\Deep Security Manager\jre\bin>keytool -import -alias root -trustcacerts -file cacert.crt -keystore "C:\Program Files\Trend Micro\Deep Security Manager\jre\lib\security\cacerts" 4. Run the following command to import the CA certificate in your keystore: C:\Program Files\Trend Micro\Deep Security Manager\jre\bin>keytool -import -alias root -trustcacerts -file cacert.crt (say yes to warning message) 5. Run the following command to import the certificate reply to your keystore: C:\Program Files\Trend Micro\Deep Security Manager\jre\bin>keytool -import -alias tomcat -file certreply.txt 6. Run the following command to view the certificate chain in you keystore: C:\Program Files\Trend Micro\Deep Security Manager\jre\bin>keytool -list -v 7. Copy the .keystore file from your user home directory C:\Documents and Settings\Administrator to C:\Program Files\ Trend Micro \Deep Security Manager\ 8. Open the configuration.properties file in folder C:\Program Files\Trend Micro\Deep Security Manager. It will look something like: keystore File=C\:\\\\Program Files\\\\Trend Micro\\\\Deep Security Manager\\\\.keystore port=4119 keystorePass=$1$85ef650a5c40bb0f914993ac1ad855f48216fd0664ed2544bbec6de80160b2f installed=true serviceName= Trend Micro Deep Security Manager 9. Replace the password in the following string: keystorePass=xxxx where "xxxx" is the password you supplied in step five 10. Save and close the file 11. Restart the Deep Security Manager service 12. Connect to the Deep Security Manager with your browser and you will notice that the new SSL certificate is signed by your CA.
- RMF Control
- SC-39
- Severity
- M
- CCI
- CCI-002530
- Version
- TMDS-00-000310
- Vuln IDs
-
- V-241167
- V-65987
- Rule IDs
-
- SV-241167r879802_rule
- SV-80477
Checks: C-44400r678724_chk
Review the Trend Deep Security server configuration to ensure a separate execution domain for each executing process is maintained. Review the network topology supporting Deep Security for separation of zones and host OS. If the architecture does separate the Deep Security Manager (DSM) from the Database, this is a finding.
Fix: F-44359r678725_fix
Configure the Trend Deep Security server to maintain a separate execution domain for each executing process. Install the Deep Security Manager on a dedicated server within a management zone. Next, connect the DSM to the assigned database provided. The database should be in separate zone with the necessary firewall rules established for communication between the application server and the DB.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- TMDS-00-000315
- Vuln IDs
-
- V-241168
- V-65989
- Rule IDs
-
- SV-241168r879806_rule
- SV-80479
Checks: C-44401r678727_chk
Review the Trend Deep Security server configuration to ensure the effects of all types of Denial of Service (DoS) attacks are protected against or limited by employing organization-defined security safeguards. Policies are templates that specify the settings and security rules to be configured and enforced automatically for one or more computers. These compact, manageable rule sets make it simple to provide comprehensive security without the need to manage thousands of rules. Default Policies provide the necessary rules for a wide range of common computer configurations. Select “Computers” from the top menu and double click on any computer from the “Computers” area. Click the “Firewall” menu and review the configuration setting under the “General” tab. If Firewall >> Configuration is set to "Off", this is a finding. Click the “Intrusion Prevention” menu and review the configuration setting under the “General” tab. If Intrusion Prevention >> Configuration is set to “Off”, this is a finding.
Fix: F-44360r678728_fix
Configure the Trend Deep Security server to protect against or limit the effects of all types of Denial of Service (DoS) attacks by employing organization-defined security safeguards. 1. Create a new Policy based on a Recommendation Scan of a computer: - On the “Computers" page, Right-click the computer, and select Actions >> Scan for Recommendations. - When the scan is complete, return to the “Policies” page and click “New” to display the “New Policy” wizard. Enter the policy name and choose “None” from the “Inherit From” option. - When prompted, choose to base the new Policy on "an existing computer's current configuration". - Select "Recommended Application Types and Intrusion Prevention Rules", "Recommended Integrity Monitoring Rules", and "Recommended Log Inspection Rules" from among the computer's properties. 2. Create a new Firewall policy based on a Recommendation Scan of a computer: - On the “Computers” page, Double-click on a computer, and select Firewall >> Scan for Open Ports. - Assign the necessary Firewall rules based on the open ports identified. Repeat for all rules as necessary.
- RMF Control
- SI-16
- Severity
- M
- CCI
- CCI-002824
- Version
- TMDS-00-000320
- Vuln IDs
-
- V-241169
- V-65991
- Rule IDs
-
- SV-241169r879821_rule
- SV-80481
Checks: C-44402r678730_chk
Review the Trend Deep Security server configuration to ensure organization-defined security safeguards are implemented to protect its memory from unauthorized code execution. Policies are templates that specify the settings and security rules to be configured and enforced automatically for one or more computers. These compact, manageable rule sets make it simple to provide comprehensive security without the need to manage thousands of rules. Default Policies provide the necessary rules for a wide range of common computer configurations. Select “Computers” from the top menu and double click on any computer from the “Computers” window. Click the “Firewall” option and review the Configuration setting under the “General” tab. If this is set to “Off”, this is a finding. Click the “Intrusion Prevention” option and review the Configuration setting under the “General” tab. If this is set to “Off”, this is a finding
Fix: F-44361r678731_fix
Configure the Trend Deep Security server to implement organization-defined security safeguards to protect its memory from unauthorized code execution. 1. Create a new Policy based on a Recommendation Scan of a computer: - On the “Computers" page, Right-click the computer, and select Actions >> Scan for Recommendations. - When the scan is complete, return to the “Policies” page and click “New” to display the “New Policy” wizard. Enter the policy name and choose “None” from the “Inherit From” option. - When prompted, choose to base the new Policy on "an existing computer's current configuration". - Select "Recommended Application Types and Intrusion Prevention Rules", "Recommended Integrity Monitoring Rules", and "Recommended Log Inspection Rules" from among the computer's properties. 2. Create a new Firewall policy based on a Recommendation Scan of a computer: - On the “Computers” page, Double-Click on a computer, and select Firewall >> Scan for Open Ports. - Assign the necessary Firewall rules based on the open ports identified. Repeat for all rules as necessary.
- RMF Control
- SI-2
- Severity
- M
- CCI
- CCI-002605
- Version
- TMDS-00-000325
- Vuln IDs
-
- V-241170
- V-65993
- Rule IDs
-
- SV-241170r879827_rule
- SV-80483
Checks: C-44403r678733_chk
Review the Trend Deep Security server configuration to ensure security-relevant software updates are installed within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs). Review the Scheduled Tasks under Administration >> Scheduled Tasks to see if “Daily Check for Security Updates” is present. If “Daily Check for Security Updates” is not present, this is a finding.
Fix: F-44362r678734_fix
Configure the Trend Deep Security server to install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs). Go to Scheduled Tasks under the “Administration” tab and click “New”. Under “Type”, select “Check for Security Updates.” Choose the” Daily” option, and click “Next”. Select a start date and time for the daily tasks, then choose “Every Day” and click “Next”. Select the computers or groups according to the organizations custom policy, and click “Next”. Enter a unique name for the scheduled task, chose the “Task Enabled” option, and click “Finish”.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002683
- Version
- TMDS-00-000330
- Vuln IDs
-
- V-241171
- V-65995
- Rule IDs
-
- SV-241171r879834_rule
- SV-80485
Checks: C-44404r678736_chk
Review the Trend Deep Security server configuration to ensure network services that have not been authorized or approved by the organization-defined authorization or approval processes are detected. Review the Intrusion Detection policy for approved ports, protocols and services associated within a defined group or a selected computer by: - Selecting “Computers”, on the top menu bar. - Choose the appropriate group and within the main page and select a computer for review. - Double click the selected computer and click “Intrusion Detection” - Verify the following settings are enabled: - Configuration: is set to On - Intrusion Prevention Behavior is set to Prevent or Detect; review local security policy for appropriate setting. - Assigned Intrusion Prevention Rules: review local security policy for appropriate setting If the Assigned Intrusion Prevention Rules do not match the local defined policy, this is a finding.
Fix: F-44363r678737_fix
Configure the Trend Deep Security server to detect network services that have not been authorized or approved by the organization-defined authorization or approval processes. To configure Deep Security to detect unauthorized services through the Intrusion Detection module, go to Policies >> Intrusion Prevention>> Select New >> New intrusion Prevention Rule - Under Details >> Application type>> Select “New” - Enter Name of the network services - Choose the appropriate direction - Select the appropriate protocol - Choose the applicable ports
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002684
- Version
- TMDS-00-000335
- Vuln IDs
-
- V-241172
- V-65997
- Rule IDs
-
- SV-241172r879835_rule
- SV-80487
Checks: C-44405r678739_chk
Review the Trend Deep Security server configuration to ensure the event is logged, and the ISSO, ISSM, and other individuals designated by the local organization are alerted when unauthorized network services are detected. Policies are templates that specify the settings and security rules to be configured and enforced automatically for one or more computers. These compact, manageable rule sets make it simple to provide comprehensive security without the need to manage thousands of rules. Default Policies provide the necessary rules for a wide range of common computer configurations. Select “Computers” from the top menu and double click on any computer from the list. Under Firewall >> General Tab >> Firewall area, verify "Configuration" is set to "On". If "Configuration" is set to “Off”, this is a finding. Under Intrusion Detection >> General Tab >> Intrusion Detection area, verify "Configuration" is set to "On". If "Configuration" is set to “Off”, this is a finding.
Fix: F-44364r678740_fix
Configure the Trend Deep Security server to log the event and alert the ISSO, ISSM, and other individuals designated by the local organization, when unauthorized network services are detected. Create a new Policy based on a Recommendation Scan of a computer. To do so, right click the computer on the “Computers” page and select Actions >> Scan for Recommendations. When the scan is complete, return to the “Policies” page and click “New” to display the “New Policy” wizard. Enter the policy name and choose “None” from the “Inherit From” option. When prompted, choose to base the new Policy on "an existing computer's current configuration". Then select "Recommended Application Types and Intrusion Prevention Rules", "Recommended Integrity Monitoring Rules", and "Recommended Log Inspection Rules" from among the computer's properties. Firewall rules should be created for each individual computer in order to prevent services from being disrupted. You can create a new Firewall policy based on a Recommendation Scan of a computer. To do so, double click on a computer on the Computers page and select Firewall >> Scan for Open Ports. Assign the necessary Firewall rules based on the open ports identified. Apply other rules as necessary.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002661
- Version
- TMDS-00-000340
- Vuln IDs
-
- V-241173
- V-65999
- Rule IDs
-
- SV-241173r879840_rule
- SV-80489
Checks: C-44406r678742_chk
Review the Trend Deep Security server configuration to ensure inbound communications traffic is continuously monitored for unusual or unauthorized activities or conditions. Verify the state of the Intrusion Prevent policies: - Select “Computers” on the top menu bar - Choose the appropriate group and within the main page and select a computer for review. - Double click the selected computer and click “Intrusion Prevention” - Verify the following settings are enabled: - Configuration: is set to Inherit or On - “State:” is listing “Activated” - Policies are defined under the Assigned Intrusion Prevention Rules. If any of these settings are not configured, this is a finding
Fix: F-44365r678743_fix
Configure the Trend Deep Security server to continuously monitor inbound communications traffic for unusual or unauthorized activities or conditions. To enable Intrusion Prevent within Deep Security, go to “Computers”, on the top menu bar. - Choose the appropriate group and within the main page and select a computer for review. - Double click the selected computer and click Intrusion Prevention. - Enable the following settings: - Configuration: Set to Inherit or On (according to local security policies) - Verify “State:” is listing “Activated” - Assign the appropriate policies under the Assigned Intrusion Prevention Rules.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002664
- Version
- TMDS-00-000345
- Vuln IDs
-
- V-241174
- V-66001
- Rule IDs
-
- SV-241174r879842_rule
- SV-80491
Checks: C-44407r678745_chk
Review the Trend Deep Security server configuration to ensure ISSO, ISSM, and other individuals designated by the local organization are alerted when the following Indicators of Compromise (IOCs) or potential compromise are detected: real time intrusion detection; threats identified by authoritative sources (e.g., CTOs); and Category I, II, IV, and VII incidents in accordance with CJCSM 6510.01B. 1. Analyze the system using the Administration >> System Settings >> Alerts tab. Review the email address listed in the “Alert Event Forwarding (From The Manager).” If this email address is not present or does not belong to a distribution group for system administrators and ISSOs, this is a finding. 2. Select Computers from the top menu and double click on any computer from the “Computers” window. Click the “Intrusion Prevention” option and review the Configuration setting under the “General” tab. If “Intrusion Prevention” is set to “Off”, this is a finding 3. Select a rule from the “Assigned Intrusion Prevention Rules” and double click to bring up the properties. Click “Options” and verify that the “Alert” tab is set to “On”. If “Alert” is set to “Off”, this is a finding.
Fix: F-44366r678746_fix
Configure the Trend Deep Security server to alert the ISSO, ISSM, and other individuals designated by the local organization when the following Indicators of Compromise (IOCs) or potential compromise are detected: real-time intrusion detection; threats identified by authoritative sources (e.g., CTOs); and Category I, II, IV, and VII incidents in accordance with CJCSM 6510.01B. Configure Events and Alerts to notify the SA and ISSO using the Administration >> System Settings >> Alerts tab. Inset a distribution email address into the “Alert Event Forwarding (From The Manager).” The distribution email address must be configured within Exchange or other email server and must associate the SA and ISSO accounts reviewing and/or managing the system. Enable Intrusion Prevention by selecting the “Computers” tab from the top menu and double click on the computer that is to be configured from list. Click Intrusion Prevention >> General. Select “On” under “Configuration”. Enable Alerts by selecting a rule from the “Assigned Intrusion Prevention Rules” by double clicking to bring up the properties. Select the “Options” tab and set the “Alert” tab to “On”.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000350
- Vuln IDs
-
- V-241175
- V-66011
- Rule IDs
-
- SV-241175r879866_rule
- SV-80501
Checks: C-44408r678748_chk
Review the Trend Deep Security server configuration to ensure audit records are generated when successful/unsuccessful attempts to modify privileges occur. Review the system using the Administration >> System Settings >> System Events tab for successful/unsuccessful attempts to delete privileges. If the options for “Record” and “Forward” are not enabled for successful/unsuccessful attempts to delete privileges, this is a finding
Fix: F-44367r678749_fix
Configure the Trend Deep Security server to generate audit records when successful/unsuccessful attempts to modify privileges occur. Configure the alert using the Administration >> System Settings >> System Events for the successful/unsuccessful attempts to delete privileges. Select the “Record” and “Forward” options for the following: - Event ID: 102 Trend Micro Deep Security Customer Account Changed - Event ID: 130 Credentials Generated - Event ID: 131 Credential Generation Failed - Event ID: 290 Group Added - Event ID: 291 Group Removed - Event ID: 291 Group Removed - Event ID: 652 User Updated - Event ID: 660 Role Created - Event ID: 651 User Deleted - Event ID: 661 Role Deleted - Event ID: 662 Role Updated - Event ID: 663 Roles Imported - Event ID: 1900 Cloud Account Added - Event ID: 1901 Cloud Account Removed - Event ID: 1902 Cloud Account Updated
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000355
- Vuln IDs
-
- V-241176
- V-66013
- Rule IDs
-
- SV-241176r879867_rule
- SV-80503
Checks: C-44409r678751_chk
Review the Trend Deep Security server configuration to ensure audit records are generated when successful/unsuccessful attempts to modify security objects occur. Review the system using the Administration >> System Settings >> System Events tab for successful/unsuccessful attempts to modify security objects. If the options for “Record” and “Forward” are not enabled for successful/unsuccessful attempts to modify security objects, this is a finding
Fix: F-44368r678752_fix
Configure the Trend Deep Security server to generate audit records when successful/unsuccessful attempts to modify security objects occur. Configure the alert using the Administration >> System Settings >> System Events for successful/unsuccessful attempts to modify security objects. Select the “Record” and “Forward” options for the following: - Event ID: 116 Rule Update Applied - Event ID: 180 Alert Type Updated - Event ID: 191 Alert Changed - Event ID: Relay Group Assigned to Computer - Event ID: 290 Group Added - Event ID: 292 Group Updated - Event ID: 306 Rebuild Baseline Requested - Event ID: 352 Policy Updated - Event ID: 378 Virtual Machine unprotected after move to another ESXi - Event ID: 412 Firewall Rule Updated - Event ID: 422 Firewall Stateful Configuration Updated - Event ID: 462 Application Type Updated - Event ID: 472 Intrusion Prevention Rule Updated - Event ID: 482 Integrity Monitoring Rule Updated - Event ID: 492 Log Inspection Rule Updated - Event ID: 507 Context Updated - Event ID: 512 IP List Updated - Event ID: 522 Port List Updated - Event ID: 532 MAC List Updated - Event ID: 542 Proxy Updated - Event ID: 552 Schedule Updated - Event ID: 575 Asset Value Updated - Event ID: 622 Access from Primary Tenant Enabled - Event ID: 623 Access from Primary Tenant Disabled - Event ID: 711 Agent Software Deployed - Event ID: 713 Agent Software Removed - Event ID: 720 Policy Sent - Event ID: 734 Computer Clock Change - Event ID: 942 Auto-Tag Rule Updated - Event ID: 1502 Malware Scan Configuration Updated - Event ID: 1512 File Extension List Updated - Event ID: 1517 File List Updated - Event ID: 1550 Web Reputation Settings Updated - Event ID: 1554 Firewall Stateful Configuration Updated - Event ID: 1555 Intrusion Prevention Configuration Updated - Event ID: 2002 Scan Cache Configuration Object Updated
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000360
- Vuln IDs
-
- V-241177
- V-66017
- Rule IDs
-
- SV-241177r879868_rule
- SV-80507
Checks: C-44410r678754_chk
Review the Trend Deep Security server configuration to ensure audit records are generated when successful/unsuccessful attempts to modify security levels occur. Review the system using the Administration >> System Settings >> System Events tab for successful/unsuccessful attempts to modify security levels. If the “Record” and “Forward” options for successful/unsuccessful attempts to modify security levels are not enabled, this is a finding.
Fix: F-44369r678755_fix
Configure the Trend Deep Security server to generate audit records when successful/unsuccessful attempts to modify security levels occur. Configure the alert using the Administration >> System Settings >> System Events tab for successful/unsuccessful attempts to modify security levels. Select the “Record” and “Forward” options for the following: - Event ID: 253 Policy Assigned to Computer - Event ID: 350 Policy Created - Event ID: 352 Policy Updated - Event ID: 720 Policy Sent - Event ID: 410 Firewall Rule Created - Event ID: 420 Firewall Stateful Configuration Created - Event ID: 460 Application Type Created - Event ID: 470 Intrusion Prevention Rule Created - Event ID: 480 Integrity Monitoring Rule Created - Event ID: 490 Log Inspection Rule Created - Event ID: 495 Log Inspection Decoder Created - Event ID: 573 Asset Value Created - Event ID: 1500 Malware Scan Configuration Created - Event ID: 1510 File Extension List Created
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000365
- Vuln IDs
-
- V-241178
- V-66019
- Rule IDs
-
- SV-241178r879870_rule
- SV-80509
Checks: C-44411r678757_chk
Review the Trend Deep Security server configuration to ensure audit records are generated when successful/unsuccessful attempts to delete privileges occur. Review the system using the Administration >> System Settings >> System Events tab for successful/unsuccessful attempts to delete privileges. If the “Record” and “Forward” options for successful/unsuccessful attempts to delete privileges are not enabled, this is a finding.
Fix: F-44370r678758_fix
Configure the Trend Deep Security server to generate audit records when successful/unsuccessful attempts to delete privileges occur. Configure the alert using the Administration >> System Settings >> System Events tab for successful/unsuccessful attempts to delete privileges. Select the “Record” and “Forward” options for the following: - Event ID: 124 Rule Update Deleted - Event ID: 661 Role Deleted - Event ID: 671 Contact Deleted - Event ID: 291 Group Removed - Event ID: 1901 Cloud Account Removed
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000375
- Vuln IDs
-
- V-241179
- V-66023
- Rule IDs
-
- SV-241179r879872_rule
- SV-80513
Checks: C-44412r678760_chk
Review the Trend Deep Security server configuration to ensure audit records are generated when successful/unsuccessful attempts to delete security objects occur. Review the system using the Administration >> System Settings >> System Events tab for successful/unsuccessful attempts to delete security objects. If the “Record” and “Forward" options for are not enabled for successful/unsuccessful attempts to delete security objects, this is a finding.
Fix: F-44371r678761_fix
Configure the Trend Deep Security server to generate audit records when successful/unsuccessful attempts to delete security objects occur. Configure the alert using the Administration >> System Settings >> System Events tab for successful/unsuccessful attempts to delete security objects. Select the “Record” and “Forward” options for the following: - Event ID: 124 Rule Update Deleted - Event ID: 152 Software Deleted - Event ID: 295 Interface Deleted - Event ID: 296 Interface IP Deleted - Event ID: 331 SSL Configuration Deleted - Event ID: 351 Policy Deleted - Event ID: 411 Firewall Rule Deleted - Event ID: 421 Firewall Stateful Configuration Deleted - Event ID: 461 Application Type Deleted - Event ID: 471 Intrusion Prevention Rule Deleted - Event ID: 481 Integrity Monitoring Rule Deleted - Event ID: 491 Log Inspection Rule Deleted - Event ID: 496 Log Inspection Decoder Deleted - Event ID: 506 Context Deleted - Event ID: 574 Asset Value Deleted - Event ID: 593 Relay Group Deleted - Event ID: 595 Event-Based Task Deleted - Event ID: 931 Certificate Deleted - Event ID: 941 Auto-Tag Rule Deleted - Event ID: 943 Tag Deleted - Event ID: 1501 Malware Scan Configuration Deleted - Event ID: 1501 Malware Scan Configuration Deleted - Event ID: 1511 File Extension List Deleted - Event ID: 1516 File List Deleted - Event ID: 1951 Tenant Deleted - Event ID: 1954 Tenant Database Server Deleted
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000380
- Vuln IDs
-
- V-241180
- V-66025
- Rule IDs
-
- SV-241180r879874_rule
- SV-80515
Checks: C-44413r678763_chk
Review the Trend Deep Security server configuration to ensure audit records are generated when successful/unsuccessful logon attempts occur. Review the system using the Administration >> System Settings >> System Events for successful/unsuccessful attempts for "User Signed In" (Event ID 600). If the options for “Record” and “Forward” are not enabled, this is a finding.
Fix: F-44372r678764_fix
Configure the Trend Deep Security server to generate audit records when successful/unsuccessful logon attempts occur. Configure the alert using the Administration >> System Settings >> System Events for successful/unsuccessful for "User Signed In" (Event ID 600). Select “Record” and “Forward”.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000385
- Vuln IDs
-
- V-241181
- V-66027
- Rule IDs
-
- SV-241181r879875_rule
- SV-80517
Checks: C-44414r678766_chk
Review the Trend Deep Security server configuration to ensure audit records are generated for privileged activities or other system-level access. Interview the ISSO for a list of functions identified as privileged within the application “System Events.” Privileged functions within the system events will include but are not limited to: Computer Created, Computer Deleted, User Added, etc. Verify the list against the Administration >> System Settings >> System Events tab. If the events are not set to “Record” and “Forward”, this is a finding.
Fix: F-44373r678767_fix
Configure the Trend Deep Security server to generate audit records for privileged activities or other system-level access. Enable the necessary privileged functions by selecting “Record” and “Forward” within the Administration >> System Settings >> System Events, system settings.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000390
- Vuln IDs
-
- V-241182
- V-66029
- Rule IDs
-
- SV-241182r879878_rule
- SV-80519
Checks: C-44415r678769_chk
Review the Trend Deep Security server to ensure audit records are generated when successful/unsuccessful accesses to objects occur. Interview the ISSO for a list of functions identified as objects that should be audited within the application “System Events.” Verify the list against the Administration >> System Settings >> System Events tab. If the events are not set to “Record” and “Forward”, this is a finding.
Fix: F-44374r678770_fix
Configure the Trend Deep Security server to generate audit records when successful/unsuccessful accesses to objects occur. Enable the necessary objects required for audit by selecting “Record” and “Forward” within the Administration >> System Settings >> System Events, system settings.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000395
- Vuln IDs
-
- V-241183
- V-66031
- Rule IDs
-
- SV-241183r879879_rule
- SV-80521
Checks: C-44416r678772_chk
Review the Trend Deep Security server to ensure audit records are generated for all direct access to the information system. Interview the ISSO for a list of direct access objects that should be audited within the application “System Events.” Verify the list against the Administration >> System Settings >> System Events tab. If the events are not set to “Record” and “Forward”, this is a finding.
Fix: F-44375r678773_fix
Configure the Trend Deep Security server to generate audit records for all direct access to the information system. Enable the necessary audit setting to capture direct access to the system by selecting “Record” and “Forward” within the Administration >> System Settings >> System Events, system settings.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000400
- Vuln IDs
-
- V-241184
- V-66033
- Rule IDs
-
- SV-241184r879880_rule
- SV-80523
Checks: C-44417r678775_chk
Review the Trend Deep Security server to ensure audit records are generated for all account creations, modifications, disabling, and termination events. Verify all creations, modifications, disabling, and termination events identified within the Trend Deep Security System Events are set to “Record” and “Forward”. If the events are not set to “Record” and “Forward”, this is a finding.
Fix: F-44376r678776_fix
Configure the Trend Deep Security server to generate audit records for all account creations, modifications, disabling, and termination events. Enable the necessary setting required for audit by selecting “Record” and “Forward” within the Administration >> System Settings >> System Events, system settings.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000172
- Version
- TMDS-00-000405
- Vuln IDs
-
- V-241185
- V-66035
- Rule IDs
-
- SV-241185r879881_rule
- SV-80525
Checks: C-44418r678778_chk
Review the Trend Deep Security server to ensure audit records are generated for all kernel module load, unload, and restart events and, also for all program initiations. Verify that audit records are off-loaded by configuring the Manager to instruct all managed computers to use Syslog: 1. Go to the Administration >> System Settings >> SIEM tab. 2. In the System Event Notification (from the Manager) area, verify the “Forward System Events to a remote computer (via Syslog)" box is checked. 3. Verify the IP address to the selected host name is entered. 4. Verify UDP port 514 or agency selected port is provided. 5. Verify the appropriate Syslog facility and Common Event Settings If any of these settings are missing from the SIEM configuration, this is a finding.
Fix: F-44377r678779_fix
Configure the Trend Deep Security server to generate audit records for all kernel module load, unload, and restart events and, also for all program initiations. To configure the Manager to instruct all managed computers to use Syslog: 1. Go to the Administration >> System Settings >> SIEM tab. 2. In the “System Event Notification (from the Manager)” area, check the “Forward System Events to a remote computer (via Syslog)” box. 3. Type the hostname or the IP address of the Syslog computer. 4. Enter which UDP port to use (usually 514). 5. Select which Syslog facility to use. 6. Select the "Common Event Format" log format. (The "Basic Syslog" format is listed only for legacy support and should not be used for new integrations).
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- TMDS-00-000410
- Vuln IDs
-
- V-241186
- V-66037
- Rule IDs
-
- SV-241186r879886_rule
- SV-80527
Checks: C-44419r678781_chk
Review the Trend Deep Security server configuration to ensure, at a minimum, off-load interconnected systems in real time and off-load standalone systems weekly. Verify that audit records are off-loaded by configuring the Manager to instruct all managed computers to use Syslog: 1. Go to the Administration >> System Settings >> SIEM tab. 2. In the System Event Notification (from the Manager) area, verify the “Forward System Events to a remote computer (via Syslog)" box is checked. 3. Verify the IP address to the selected host name is entered. 4. Verify UDP port 514 or agency selected port is provided. 5. Verify the appropriate Syslog facility and Common Event Settings If any of these settings are missing from the SIEM configuration, this is a finding.
Fix: F-44378r678782_fix
Configure the Trend Deep Security server to, at a minimum, off-load interconnected systems in real time and off-load standalone systems weekly. To configure the Manager to instruct all managed computers to use Syslog: 1. Go to the Administration >> System Settings >> SIEM tab. 2. In the “System Event Notification (from the Manager)” area, check the “Forward System Events to a remote computer (via Syslog)” box. 3. Type the hostname or the IP address of the Syslog computer. 4. Enter which UDP port to use (usually 514). 5. Select which Syslog facility to use. 6. Select the "Common Event Format" log format. (The "Basic Syslog" format is listed only for legacy support and should not be used for new integrations).
- RMF Control
- SI-6
- Severity
- M
- CCI
- CCI-002702
- Version
- TMDS-00-002125
- Vuln IDs
-
- V-241187
- V-66005
- Rule IDs
-
- SV-241187r879845_rule
- SV-80495
Checks: C-44420r678784_chk
Review the Trend Deep Security server configuration to ensure the system administrator is notified when anomalies in the operation of the security functions are discovered. Verify Intrusion Prevention is enabled for all connected host systems by navigating to Policy >> Policy Editor. Navigate to Intrusion Prevention >> General, verify that the intrusion prevention module is "On" and configured with assigned rules. If "Intrusion Prevention" is not set to "On", this is a finding.
Fix: F-44379r678785_fix
Configure the Trend Deep Security sever to notify the system administrator when anomalies in the operation of the security functions are discovered. To enable Intrusion Prevention functionality on a computer: In the Policy/Computer editor, go to Intrusion Prevention >> General Select "On", and then click "Assign/Unassign". Select the appropriate rules applicable to the information system being monitored. Click "Save".
- RMF Control
- SI-7
- Severity
- M
- CCI
- CCI-002715
- Version
- TMDS-00-002130
- Vuln IDs
-
- V-241188
- V-66007
- Rule IDs
-
- SV-241188r879851_rule
- SV-80497
Checks: C-44421r678787_chk
Review the Trend Deep Security server configuration to ensure security safeguards are implemented when integrity violations are discovered. Verify Integrity Monitoring is enabled for all connected host systems by navigating to Policy >> Policy Editor. Navigate to Integrity Monitoring >> General, verify that the Integrity Monitoring module is "On" and configured with assigned rules. If "Integrity Monitoring" is not set to "On", this is a finding.
Fix: F-44380r678788_fix
Configure the Trend Deep Security server to implement security safeguards when integrity violations are discovered. To enable Integrity Monitoring functionality on a computer: In the Policy/Computer editor, go to Integrity Monitoring >> General Select "On", and then click "Assign/Unassign". Select the appropriate rules applicable to the information system being monitored. Click "Save".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- TMDS-00-004515
- Vuln IDs
-
- V-241189
- V-66043
- Rule IDs
-
- SV-241189r879887_rule
- SV-80533
Checks: C-44422r678790_chk
Review the Trend Deep Security server to ensure synchronization occurs with Active Directory on a daily (or AO-defined) basis. Under Administration >> Scheduled Tasks, review the scheduled tasks listed for "Daily Sync Users". If a task for syncing user's accounts with AD does not exist, this is a finding.
Fix: F-44381r678791_fix
Configure the Trend Deep Security server to synchronize with Active Directory on a daily (or AO-defined) basis. Under Administration >> Scheduled Tasks, click "New". From the "Type" drop down menu, select "Synchronize Users/Contacts". Select "Daily", and click "Next". Enter start date, start time, and select "Every Day". Click "Next". Enter a unique name for this scheduled task or leave the default. Check the box for" Task Enabled", click "Finish".
- RMF Control
- CM-6
- Severity
- H
- CCI
- CCI-000366
- Version
- TMDS-00-004520
- Vuln IDs
-
- V-241190
- V-66045
- Rule IDs
-
- SV-241190r879887_rule
- SV-80535
Checks: C-44423r678793_chk
Review the Web Server hosting Trend Deep Security to ensure multifactor authentication has been configured. 1. Open Internet Information Services (IIS) Manager. 2. In the console tree, expand the server name. 3. In the server Home page, double-click Authentication to open the Authentication page. 4. In the Authentication page, right-click AD Client Certificate Authentication, and ensure "Enable" is selected. 5. Close the Authentication page. 6. In the server Home page, double-click SSL Settings to open the SSL Settings page. 7. Ensure the "Require SSL" Checkbox is checked, and "Require" radio button is selected. 8. Close the SSL Settings page. 9. Close IIS Manager. If "Enable" is not selected in the Authentication page, this is a finding. If "Require SSL" is not selected in the SSL Settings page, this is a finding. If "Ignore" or "Accept" radio buttons are selected in the SSL settings page, this is a finding.
Fix: F-44382r678794_fix
Configure the Web Server hosting Trend Deep Security for multifactor authentication. To configure the authentication method in IIS: 1. Open Internet Information Services (IIS) Manager. 2. In the console tree, expand the server name. 3. In the server Home page, double-click Authentication to open the Authentication page. 4. In the Authentication page, right-click AD Client Certificate Authentication, and click "Enable". 5. Close the Authentication page. 6. In the server Home page, double-click SSL Settings to open the SSL Settings page. 7. Select the "Require SSL" Checkbox, and "Require" radio button. 8. Close the SSL Settings page. 9. Close IIS Manager.
- RMF Control
- IA-2
- Severity
- H
- CCI
- CCI-000770
- Version
- TMDS-00-006030
- Vuln IDs
-
- V-241191
- V-65913
- Rule IDs
-
- SV-241191r879594_rule
- SV-80403
Checks: C-44424r678796_chk
Review the Trend Deep Security server to ensure users are authenticated with an individual authenticator prior to using a group authenticator. Review the settings to ensure identify management is being performed through the organizations Active Directory. Navigate to Administration >> User Management >> Users and click "Synchronize with Directory". Select "Re-Synchronize (Using previous settings)", and click "Next". If the synchronization fails, this is a finding.
Fix: F-44383r678797_fix
Configure the Trend Deep Security server to authenticate users with an individual authenticator prior to using a group authenticator. Navigate to Administration >> User Management >> Users and click "Synchronize with Directory". Under Server, enter the following information: Server Address (IP of the AD Server) Access Method (UserID/Password StartTLS) UserName (Authorized, site-defined, service account used for synchronizing with Trend Deep Security) Password Click "Next". Select the authorized AD group used for managing the Trend Deep Security accounts, and Click "Next". Under "New User" Options, select the appropriate Role, click "Next". Click "Finish".
- RMF Control
- SI-2
- Severity
- H
- CCI
- CCI-002605
- Version
- TMDS-00-009999
- Vuln IDs
-
- V-259713
- Rule IDs
-
- SV-259713r942481_rule
Checks: C-63452r942480_chk
Trend Deep Security 9.x is no longer supported by the vendor. If the system is running Trend Deep Security 9.x, this is a finding.
Fix: F-53958r798705_fix
Upgrade to a supported version.