Trend Micro TippingPoint IDPS Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002346
- Version
- TIPP-IP-000010
- Vuln IDs
-
- V-242167
- Rule IDs
-
- SV-242167r710044_rule
Checks: C-45442r710042_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "database". If the filter settings are not set for each to "Use Category Settings" or there are filter items disabled that are outside of recommended Trend Micro settings, this is a finding.
Fix: F-45400r710043_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "database". 5. Ensure all items in the search results have "Use Category Settings" selected.
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002346
- Version
- TIPP-IP-000020
- Vuln IDs
-
- V-242168
- Rule IDs
-
- SV-242168r710047_rule
Checks: C-45443r710045_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". Under "Filter criteria", select all "Filter categories". 4. Select the "Filter Name" section and type "database", and select HTTP under "Filter Taxonomy Criteria as the Protocol". If the filter settings are not set for each to "Use Category Settings" or there are filter items disabled that are outside of recommended Trend Micro settings, this is a finding.
Fix: F-45401r710046_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Then select the "Filter Name" section and type "database", and select HTTP under "Filter Taxonomy Criteria as the Protocol". 5. Ensure all items in the search results have "Use Category Settings" selected.
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002346
- Version
- TIPP-IP-000030
- Vuln IDs
-
- V-242169
- Rule IDs
-
- SV-242169r710050_rule
Checks: C-45444r710048_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "database". If the filter settings are not set for each to "Use Category Settings" or there are filter items disabled that are outside of recommended Trend Micro settings, this is a finding.
Fix: F-45402r710049_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "database". 5. Ensure all items in the search results have "Use Category Settings" selected.
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002347
- Version
- TIPP-IP-000040
- Vuln IDs
-
- V-242170
- Rule IDs
-
- SV-242170r710053_rule
Checks: C-45445r710051_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "database". If the filter settings are not set for each to "Use Category Settings" or there are filter items disabled that are outside of recommended Trend Micro settings, this is a finding.
Fix: F-45403r710052_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "database". 5. Ensure all items in the search results have "Use Category Settings" selected.
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002347
- Version
- TIPP-IP-000050
- Vuln IDs
-
- V-242171
- Rule IDs
-
- SV-242171r710056_rule
Checks: C-45446r710054_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "database", and select HTTP under "Filter Taxonomy Criteria as the Protocol". If the filter settings are not set for each to "Use Category Settings" or there are filter items disabled that are outside of recommended Trend Micro settings, this is a finding.
Fix: F-45404r710055_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "database", and select HTTP under "Filter Taxonomy Criteria as the Protocol". 5. Ensure all items in the search results have "Use Category Settings" selected.
- RMF Control
- AC-23
- Severity
- M
- CCI
- CCI-002347
- Version
- TIPP-IP-000060
- Vuln IDs
-
- V-242172
- Rule IDs
-
- SV-242172r710059_rule
Checks: C-45447r710057_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "database". If the filter settings are not set for each to "Use Category Settings" or there are filter items disabled that are outside of recommended Trend Micro settings, this is a finding.
Fix: F-45405r710058_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "database". 5. Ensure all items in the search results have "Use Category Settings" selected.
- RMF Control
- AC-4
- Severity
- H
- CCI
- CCI-001368
- Version
- TIPP-IP-000070
- Vuln IDs
-
- V-242173
- Rule IDs
-
- SV-242173r710062_rule
Checks: C-45448r710060_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Ensure the deployment mode of "Security-Optimized" is selected. The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview" and ensure the action set for each category is set to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon. If the "security-optimized" deployment mode is not configured, this is a finding.
Fix: F-45406r710061_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is no profile configured, select "default". 3. Click "Edit Details". Select the deployment mode of "Security-Optimized". The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview", and select the action set for each category to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon.
- RMF Control
- AC-4
- Severity
- H
- CCI
- CCI-001414
- Version
- TIPP-IP-000080
- Vuln IDs
-
- V-242174
- Rule IDs
-
- SV-242174r754436_rule
Checks: C-45449r710063_chk
1. In the Trend Micro SMS, navigate to "Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Then select "Traffic Management". 4. Ensure there are traffic management filters for each zone based on unapproved traffic directions. For example, if traffic from the management network is not allowed to access the external network, look for this rule. If a rule is not in place to enforce this, this is a finding.
Fix: F-45407r710064_fix
1. In the Trend Micro SMS, navigate to "Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Then select "Traffic Management". 4. Select "New" then type a name. For example, "Management network blocked to internet". 5. Ensure block is selected. 6. Add necessary comment. 7. Ensure the direction A to B, or B to A is identified. 8. Enter the following for detailed addressing: a. Select IP for IPv4 or IPv6 for IPv6. b. Under Source Address type the subnet for the management network. c. Under destination address, select any. This is an example of blocking management traffic from accessing internet communications. Add additional traffic management rules to block or allow traffic based on IPv4 or IPv6 protocol, ICMP/ICMPv6 types, and/or source and destination addresses and TCP/UDP ports.
- RMF Control
- AC-4
- Severity
- M
- CCI
- CCI-001414
- Version
- TIPP-IP-000090
- Vuln IDs
-
- V-242175
- Rule IDs
-
- SV-242175r710068_rule
Checks: C-45450r710066_chk
1. In the Trend Micro SMS interface, go to the "Profiles" and then "Digital Vaccines". 2. Check the latest DV version that is downloaded/imported and is active. Go the Trend Micro support system located here: https://tmc.tippingpoint.com/TMC/Releases 3. Under Digital Vaccines, select the DV major version (3.2.0 currently). 4. Ensure the latest signature release is the current one that is applied to the SMS and is active to all TPS systems in the network. If the latest one is not applied as the Active DV version, this is a finding.
Fix: F-45408r710067_fix
1. In the Trend Micro SMS interface, go to the "Profiles" and then "Digital Vaccines". 2. Check the latest DV version that is downloaded/imported and is active. Go the Trend Micro support system located here: https://tmc.tippingpoint.com/TMC/Releases 3. Under Digital Vaccines, select the DV major version (3.2.0 currently). 4. Download the latest signature file (e.g. SIG_3.2.0_9404.pkg). 5. Read the EULA acceptance notice, then select Accept. 6. Under an approved network change window, go back to the SMS, Profiles, and Digital Vaccines. 7. Select "import", then select the file downloaded from the TMC site. 8. Once prompted, select distribute to all TPS devices in the network.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- TIPP-IP-000100
- Vuln IDs
-
- V-242176
- Rule IDs
-
- SV-242176r710071_rule
Checks: C-45451r710069_chk
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. If a syslog server is not configured to send the following audit logs, this is a finding: - Device Audit - Device System - SMS Audit - SMS system
Fix: F-45409r710070_fix
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. 3. Click "New". 4. Under syslog server type the hostname or IP address of the syslog server. 5. Click TCP to ensure logging data is queued in the case of disconnection of the syslog server. 6. Type the port used by the centralized logging server (traditionally it is port 514). 7. Under log type, select "Device Audit". 8. Under facility click "Log Audit". 9. Click Event timestamp under "Include Timestamp in Header". 10. Select "include SMS hostname in header". Repeat this once more, changing the Log Type to include SMS Audit.
- RMF Control
- AU-12
- Severity
- M
- CCI
- CCI-000169
- Version
- TIPP-IP-000110
- Vuln IDs
-
- V-242177
- Rule IDs
-
- SV-242177r710074_rule
Checks: C-45452r710072_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Additional Criteria" section. 5. Uncheck "permit" and "rate limit", then click Search. 6. Once the results are presented, check the "Action Set" column to filter by action type. If any items state "Block" but not "Block/Notify", this is a finding.
Fix: F-45410r710073_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Additional Criteria" section. 5. Uncheck "permit" and "rate limit", then click "Search". 6. Once the results are presented, click the "Action Set" column to filter by action type. If any items state "Block": a. Double-click the item. b. Click the radio button for "User Filter settings". c. On the drop down-menu, select "Block + Notify". d. Click "OK". e. Once under an approved change window, click distribute and send the updated policy to all TPS systems and managed segment-groups. f. Ensure progress completes at 100%.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000130
- Version
- TIPP-IP-000120
- Vuln IDs
-
- V-242178
- Rule IDs
-
- SV-242178r710348_rule
Checks: C-45453r710075_chk
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. If a syslog server is not configured to send the following audit logs, this is a finding: - Device Audit - Device System - SMS Audit - SMS system
Fix: F-45411r710076_fix
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. Click "New". 3. Under syslog server type the hostname or IP address of the syslog server. 4. Click TCP to ensure logging data is queued in the case of disconnection of the syslog server. 5. Type the port used by the centralized logging server (traditionally it is port 514). 6. Under log type, select Device Audit. 7. Under facility click "Log Audit". 8. Click Event timestamp under "Include Timestamp in Header". 9. Select "include SMS hostname in header". Repeat this three more times changing the Log Type to include Device System, SMS Audit, and SMS System.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000131
- Version
- TIPP-IP-000130
- Vuln IDs
-
- V-242179
- Rule IDs
-
- SV-242179r710080_rule
Checks: C-45454r710078_chk
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. If a syslog server is not configured to send the following audit logs, this is a finding: - Device Audit - Device System - SMS Audit - SMS system
Fix: F-45412r710079_fix
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. Click "New". 3. Under syslog server type the hostname or IP address of the syslog server. 4. Click TCP to ensure logging data is queued in the case of disconnection of the syslog server. 5. Type the port used by the centralized logging server (traditionally it is port 514). 6. Under log type, select Device Audit. 7. Under facility click "Log Audit". 8. Click Event timestamp under "Include Timestamp in Header". 9. Select "include SMS hostname in header". Repeat this three more times changing the Log Type to include Device System, SMS Audit, and SMS System.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000132
- Version
- TIPP-IP-000140
- Vuln IDs
-
- V-242180
- Rule IDs
-
- SV-242180r710347_rule
Checks: C-45455r710081_chk
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. If a syslog server is not configured to send the following audit logs, this is a finding: - Device Audit - Device System - SMS Audit - SMS system
Fix: F-45413r710082_fix
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. Click "New". 3. Under syslog server type the hostname or IP address of the syslog server. 4. Click TCP to ensure logging data is queued in the case of disconnection of the syslog server. 5. Type the port used by the centralized logging server (traditionally it is port 514). 6. Under log type, select Device Audit. 7. Under facility click "Log Audit". 8. Click Event timestamp under "Include Timestamp in Header". 9. Select "include SMS hostname in header". Repeat this three more times changing the Log Type to include Device System, SMS Audit, and SMS System.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000133
- Version
- TIPP-IP-000150
- Vuln IDs
-
- V-242181
- Rule IDs
-
- SV-242181r710086_rule
Checks: C-45456r710084_chk
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. If a syslog server is not configured to send the following audit logs, this is a finding: - Device Audit - Device System - SMS Audit - SMS system
Fix: F-45414r710085_fix
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. Click "New". 3. Under syslog server type the hostname or IP address of the syslog server. 4. Click TCP to ensure logging data is queued in the case of disconnection of the syslog server. 5. Type the port used by the centralized logging server (traditionally it is port 514). 6. Under log type, select Device Audit. 7. Under facility click "Log Audit". 8. Click Event timestamp under "Include Timestamp in Header". 9. Select "include SMS hostname in header". Repeat this three more times changing the Log Type to include Device System, SMS Audit, and SMS System.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-000134
- Version
- TIPP-IP-000160
- Vuln IDs
-
- V-242182
- Rule IDs
-
- SV-242182r710346_rule
Checks: C-45457r710087_chk
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. If a syslog server is not configured to send the following audit logs, this is a finding: - Device Audit - Device System - SMS Audit - SMS system
Fix: F-45415r710088_fix
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. Click "New". 3. Under syslog server type the hostname or IP address of the syslog server. 4. Click TCP to ensure logging data is queued in the case of disconnection of the syslog server. 5. Type the port used by the centralized logging server (traditionally it is port 514). 6. Under log type, select Device Audit. 7. Under facility click "Log Audit". 8. Click Event timestamp under "Include Timestamp in Header". 9. Select "include SMS hostname in header". Repeat this three more times changing the Log Type to include Device System, SMS Audit, and SMS System.
- RMF Control
- AU-3
- Severity
- M
- CCI
- CCI-001844
- Version
- TIPP-IP-000170
- Vuln IDs
-
- V-242183
- Rule IDs
-
- SV-242183r710092_rule
Checks: C-45458r710090_chk
Under the TPS serial CLI console type the following command: show sms. If the output of the command is not "Device is under SMS control", this is a finding.
Fix: F-45416r710091_fix
1. On the SMS, go to "Devices" and click "all devices". 2. Click "New Device". 3. Under "Add device" enter the IPv4 or IPv6 address of the TPS to be managed by SMS. 4. Under "Authentication" add the device username and password that was configured upon initial TPS setup. 5. Select which device group it should be part of. 6. Ensure it is under the IPS/TPS device type. 7. Click OK. 8. Ensure the device connects and is managed by the SMS. 9. On the serial console of the TPS type the command: show sms, and ensure it is now being controlled by SMS.
- RMF Control
- AU-4
- Severity
- M
- CCI
- CCI-001851
- Version
- TIPP-IP-000180
- Vuln IDs
-
- V-242184
- Rule IDs
-
- SV-242184r710095_rule
Checks: C-45459r710093_chk
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. If a syslog server is not configured to send the following audit logs, this is a finding: - Device Audit - Device System - SMS Audit - SMS system
Fix: F-45417r710094_fix
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. 3. Click "New". 4. Under syslog server type the hostname or IP address of the syslog server. 5. Click TCP to ensure logging data is queued in the case of disconnection of the syslog server. 6. Type the port used by the centralized logging server (traditionally it is port 514). 7. Under log type, select "Device Audit". 8. Under facility click "Log Audit". 9. Click Event timestamp under "Include Timestamp in Header". 10. Select "Include SMS hostname in header". Repeat this three more times changing the Log Type to include Device System, SMS Audit, and SMS System.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000140
- Version
- TIPP-IP-000190
- Vuln IDs
-
- V-242185
- Rule IDs
-
- SV-242185r710345_rule
Checks: C-45460r710096_chk
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. If each syslog setting is not configured with TCP as the protocol, this is a finding.
Fix: F-45418r710097_fix
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. 3. Click "New". 4. Under syslog server type the hostname or IP address of the syslog server. 5. Click TCP to ensure logging data is queued in the case of disconnection of the syslog server. 6. Type the port used by the centralized logging server (traditionally it is port 514). 7. Under log type, select "Device Audit". 8. Under facility click "Log Audit". 9. Click Event timestamp under "Include Timestamp in Header". 10. Select "include SMS hostname in header". Repeat this three more times changing the Log Type to include Device System, SMS Audit, and SMS System.
- RMF Control
- AU-5
- Severity
- M
- CCI
- CCI-000140
- Version
- TIPP-IP-000200
- Vuln IDs
-
- V-242186
- Rule IDs
-
- SV-242186r710101_rule
Checks: C-45461r710099_chk
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Database". Each item in the database maintenance section has a configurable item to ensure when the newest logs will overwrite the oldest logs. This is configured through the number of rows: a. The Events log must be set to at least 30,000,000 rows, with an age of 90 days. b. The Audit Log must be set 1,000,000 rows and an age of 365 days. c. The Device Audit Log must be set 1,000,000 rows and an age of 365 days. d. The Device System Log must be set 1,000,000 rows and an age of 365 days. If these values are not set, this is a finding.
Fix: F-45419r710100_fix
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Database". 2. Make the following changes: a. The Events log must be set to at least 30,000,000 rows, with an age of 90 days. b. The Audit Log must be set 1,000,000 rows and an age of 365 days. c. The Device Audit Log must be set 1,000,000 rows and an age of 365 days. d. The Device System Log must be set 1,000,000 rows and an age of 365 days.
- RMF Control
- AU-6
- Severity
- M
- CCI
- CCI-000154
- Version
- TIPP-IP-000210
- Vuln IDs
-
- V-242187
- Rule IDs
-
- SV-242187r710104_rule
Checks: C-45462r710102_chk
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. If a syslog server is not configured to send the following audit logs, this is a finding: - Device System - SMS system
Fix: F-45420r710103_fix
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. 3. Click "New". 4. Under syslog server type the hostname or IP address of the syslog server. 5. Click TCP to ensure logging data is queued in the case of disconnection of the syslog server. 6. Type the port used by the centralized logging server (traditionally it is port 514). 7. Under log type, select "Device System". 8. Under facility click "Log System". 9. Click Event timestamp under "Include Timestamp in Header". 10. Select "Include SMS hostname in header". Repeat this one more time changing the Log Type to include SMS System.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- TIPP-IP-000230
- Vuln IDs
-
- V-242188
- Rule IDs
-
- SV-242188r710107_rule
Checks: C-45463r710105_chk
1. In the Trend Micro SMS interface, go to the "Devices" tab". 2. Select the Device to be modified. 3. Click "Device Configuration" and "Services". If SSH is enabled, this is a finding. Under "FIPS Settings", if the box is unchecked, this is a finding.
Fix: F-45421r710106_fix
1. In the Trend Micro SMS interface, go to the "Devices" tab". 2. Then Select the Device to be modified. 3. Click "Device Configuration" and "Services". 4. Uncheck enabled for SSH. 5. Go to "FIPS Settings", select "enabled" for "FIPS Mode". 6. Click OK. CAUTION: This should be done under an approved maintenance window, as selecting FIPS Mode will cause the TPS to reboot.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001166
- Version
- TIPP-IP-000240
- Vuln IDs
-
- V-242189
- Rule IDs
-
- SV-242189r710110_rule
Checks: C-45464r710108_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". 4. Ensure the deployment mode of "Security-Optimized" is selected. The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 5. Navigate to "Profile Overview" and ensure the action set for each category is set to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon. If the "security-optimized" deployment mode is not configured, this is a finding.
Fix: F-45422r710109_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Select the deployment mode of "Security-Optimized". The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview", and select the action set for each category to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon.
- RMF Control
- SC-18
- Severity
- M
- CCI
- CCI-001662
- Version
- TIPP-IP-000250
- Vuln IDs
-
- V-242190
- Rule IDs
-
- SV-242190r710113_rule
Checks: C-45465r710111_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Ensure the deployment mode of "Security-Optimized" is selected. The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview" and ensure the action set for each category is set to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon. If the "security-optimized" deployment mode is not configured, this is a finding.
Fix: F-45423r710112_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Select the deployment mode of "Security-Optimized". The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview", and select the action set for each category to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon.
- RMF Control
- SC-24
- Severity
- M
- CCI
- CCI-001190
- Version
- TIPP-IP-000260
- Vuln IDs
-
- V-242191
- Rule IDs
-
- SV-242191r710116_rule
Checks: C-45466r710114_chk
1. In the Trend Micro SMS, navigate to "Devices". 2. Select the device that will be modified, then select "Network Configuration". If any of the Intrinsic HA items state Permit All, this is a finding.
Fix: F-45424r710115_fix
1. In the Trend Micro SMS, navigate to "Devices". 2. Select the device that will be modified, then select "Network Configuration". 3. Click each segment that is currently operational. a. Click "Edit". b. Under "Link Down Synchronization" select "Block All" and ensure the Link Down Synchronization Mode is "Wire" and 1 second wait time. c. Select Finish.
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-002385
- Version
- TIPP-IP-000270
- Vuln IDs
-
- V-242192
- Rule IDs
-
- SV-242192r710119_rule
Checks: C-45467r710117_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "ddos". If the following filter names are not set to Block+Notify, this is a finding: - 10725: TCP: LOIC DDoS Tool - 12624: TCP: itsoknoproblembro DDoS Tool - 12641: UDP: itsoknoproblembro DDoS Tool - 12899: HTTP: Vertigo DDoS Tool - 19918: HTTP: Kill 'em All DDOS Attack
Fix: F-45425r710118_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "ddos". 5. Ensure all the following are set to Block+Notify: - 10725: TCP: LOIC DDoS Tool - 12624: TCP: itsoknoproblembro DDoS Tool - 12641: UDP: itsoknoproblembro DDoS Tool - 12899: HTTP: Vertigo DDoS Tool - 19918: HTTP: Kill 'em All DDOS Attack
- RMF Control
- SC-5
- Severity
- M
- CCI
- CCI-001095
- Version
- TIPP-IP-000280
- Vuln IDs
-
- V-242193
- Rule IDs
-
- SV-242193r710122_rule
Checks: C-45468r710120_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". Under "advanced DDoS", if a DDoS filter does not exist, this is a finding.
Fix: F-45426r710121_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "advanced DDoS", select New. a. Under Filter Parameters, type a name. b. Select Block + Notify as the action set. c. Determine which port-pair direction is the outbound direction. For example, if the outbound traffic direction is Port A to Port B, select "Port A to Port B" as the direction. d. Select "Any" for the destination IP. e. Select SYN Proxy Settings. f. Click "enabled". g. Type a notification threshold of SYN transmits per second. The range is 1–10000. Consult with the ISSO to ensure this range will meet organizational policy. h. Under an approved change window, select Distribute to the TPS.
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- TIPP-IP-000290
- Vuln IDs
-
- V-242194
- Rule IDs
-
- SV-242194r710125_rule
Checks: C-45469r710123_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Traffic Management". If there are no ICMP Destination Unreachable, Redirect, and Address Mask reply message policies defined, this is a finding.
Fix: F-45427r710124_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Traffic Management". Create a separate policy for each type of ICMP message. 4. Click New. a. Under name type a name. b. Action: Block c. Direction: Ensure the direction for Outbound ports are selected correctly. d. Protocol: ICMP e. Type: 3 f. Source address: any g. Destination Address: any h. Repeat previous steps for Types 5 and 18.
- RMF Control
- SI-11
- Severity
- M
- CCI
- CCI-001312
- Version
- TIPP-IP-000300
- Vuln IDs
-
- V-242195
- Rule IDs
-
- SV-242195r710128_rule
Checks: C-45470r710126_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "icmp". If the following filter names are not set to Block+Notify, this is a finding: 7141: ICMP: Header Incomplete 7145: ICMPv6: Header Incomplete 0087: ICMP: Modem Hangup (+++ATH) Echo Request 0110: TFN: ICMP Flood Command Acknowledgement (General) 0282: ICMP: icmpenum (Timestamp Request) 0283: ICMP: icmpenum (Information Request) 1474: ICMP: Modem Hangup (+++ATH) Echo Reply 3852: NTRootKit: Command and Control Response (ICMP) 5855: ICMP: Malicious Router Discovery Protocol Packet 10043: ICMP: Solaris 10 ICMP Remote DoS 12522: ICMP: Source Quench 12577: ICMP: Destination Unreachable (Fragmentation Needed and DF Bit Set) 13118: ICMP: Windows DirectAccess Server IPv6 Invalid Header Denial-of-Service Vulnerability 13172: ICMP: Active Directory LDAP Winsock Denial-of-Service Vulnerability 13532: IPv6: Microsoft Windows ICMPv6 Prefix Update Denial-of-Service Vulnerability 17049: ICMPv6: FreeBSD rtsold Buffer Overflow Vulnerability 17086: ICMP: Regin Malware Communication Attempt 22646: ICMPv6: FreeBSD SCTP ICMPv6 Denial-of-Service Vulnerability 29732: ICMP: Dnsmasq ICMPv6 Router Advertisement Buffer Overflow Vulnerability 0081: ICMP: Unassigned Type (Type 1) 0081: ICMP: Unassigned Type (Type 1) ICMPv6 Types 144 through 153
Fix: F-45428r710127_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Search". 4. Under "Filter criteria", select all "Filter categories". Select the "Filter Name" section and type "icmp". 5. Click each of the following rules and select: 7141: ICMP: Header Incomplete 7145: ICMPv6: Header Incomplete 0087: ICMP: Modem Hangup (+++ATH) Echo Request 0110: TFN: ICMP Flood Command Acknowledgement (General) 0282: ICMP: icmpenum (Timestamp Request) 0283: ICMP: icmpenum (Information Request) 1474: ICMP: Modem Hangup (+++ATH) Echo Reply 3852: NTRootKit: Command and Control Response (ICMP) 5855: ICMP: Malicious Router Discovery Protocol Packet 10043: ICMP: Solaris 10 ICMP Remote DoS 12522: ICMP: Source Quench 12577: ICMP: Destination Unreachable (Fragmentation Needed and DF Bit Set) 13118: ICMP: Windows DirectAccess Server IPv6 Invalid Header Denial-of-Service Vulnerability 13172: ICMP: Active Directory LDAP Winsock Denial-of-Service Vulnerability 13532: IPv6: Microsoft Windows ICMPv6 Prefix Update Denial-of-Service Vulnerability 17049: ICMPv6: FreeBSD rtsold Buffer Overflow Vulnerability 17086: ICMP: Regin Malware Communication Attempt 22646: ICMPv6: FreeBSD SCTP ICMPv6 Denial-of-Service Vulnerability 29732: ICMP: Dnsmasq ICMPv6 Router Advertisement Buffer Overflow Vulnerability 0081: ICMP: Unassigned Type (Type 1) 0081: ICMP: Unassigned Type (Type 1) ICMPv6 Types 144 through 153
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001247
- Version
- TIPP-IP-000320
- Vuln IDs
-
- V-242196
- Rule IDs
-
- SV-242196r710131_rule
Checks: C-45471r710129_chk
1. In the Trend Micro SMS, navigate to "Profiles", and "Digital Vaccines". 2. Under "Auto DV Activation", if "Automatic Download", and "Automatic Activation" are not enabled, this is a finding.
Fix: F-45429r710130_fix
1. In the Trend Micro SMS, navigate to "Profiles", and "Digital Vaccines". 2. Under "Auto DV Activation", select edit. a. Check Automatic Download. b. Check Automatic Activation. c. Click OK.
- RMF Control
- SI-3
- Severity
- H
- CCI
- CCI-001240
- Version
- TIPP-IP-000330
- Vuln IDs
-
- V-242197
- Rule IDs
-
- SV-242197r754437_rule
Checks: C-45472r710132_chk
1. In the Trend Micro SMS, navigate to "Profiles", and "Digital Vaccines". 2. Under "Auto DV Activation" if "Automatic Download", and "Automatic Activation" are not enabled, this is a finding.
Fix: F-45430r710133_fix
1. In the Trend Micro SMS, navigate to "Profiles", and "Digital Vaccines". 2. Under "Auto DV Activation", select edit. a. Check Automatic Download. b. Check Automatic Activation. c. Click OK.
- RMF Control
- SI-3
- Severity
- M
- CCI
- CCI-001243
- Version
- TIPP-IP-000350
- Vuln IDs
-
- V-242198
- Rule IDs
-
- SV-242198r710137_rule
Checks: C-45473r710135_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Ensure the deployment mode of "Security-Optimized" is selected. The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview" and ensure the action set for each category is set to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon. If the "security-optimized" deployment mode is not configured, this is a finding.
Fix: F-45431r710136_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Select the deployment mode of "Security-Optimized". The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview", and select the action set for each category to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon.
- RMF Control
- SI-3
- Severity
- H
- CCI
- CCI-001242
- Version
- TIPP-IP-000360
- Vuln IDs
-
- V-242199
- Rule IDs
-
- SV-242199r754438_rule
Checks: C-45474r710138_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Shared Settings". 2. Under "Action Sets, if "Remote Syslog", are not enabled for both the "Block+Notify" and "Block+Notify+Trace", this is a finding.
Fix: F-45432r710139_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Shared Settings". 2. Under "Action Sets: a. Select "Block+Notify" and edit. b. Select Notifications, and check "Remote Syslog". c. Select "Finish".
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002656
- Version
- TIPP-IP-000370
- Vuln IDs
-
- V-242200
- Rule IDs
-
- SV-242200r710143_rule
Checks: C-45475r710141_chk
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. If a syslog server is not configured to send the following audit logs, this is a finding: - Device Audit - Device System - SMS Audit - SMS system
Fix: F-45433r710142_fix
1. In the Trend Micro SMS interface, go to the "Admin" tab, and select "Server Properties". 2. Select the "syslog" tab. Click "New". 3. Under syslog server type the hostname or IP address of the syslog server. 4. Click TCP to ensure logging data is queued in the case of disconnection of the syslog server. 5. Type the port used by the centralized logging server (traditionally it is port 514). 6. Under log type, select "Device Audit". 7. Under facility click "Log Audit". 8. Click Event timestamp under "Include Timestamp in Header". 9. Select "include SMS hostname in header". Repeat this three more times changing the Log Type to include Device System, SMS Audit, and SMS System.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002683
- Version
- TIPP-IP-000380
- Vuln IDs
-
- V-242201
- Rule IDs
-
- SV-242201r710146_rule
Checks: C-45476r710144_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Ensure the deployment mode of "Security-Optimized" is selected. The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview" and ensure the action set for each category is set to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon. If the "security-optimized" deployment mode is not configured, this is a finding.
Fix: F-45434r710145_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details"; select the deployment mode of "Security-Optimized". The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview" and select the action set for each category to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002684
- Version
- TIPP-IP-000400
- Vuln IDs
-
- V-242202
- Rule IDs
-
- SV-242202r710149_rule
Checks: C-45477r710147_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Ensure the deployment mode of "Security-Optimized" is selected. The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview" and ensure the action set for each category is set to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon. If the "security-optimized" deployment mode is not configured, this is a finding.
Fix: F-45435r710148_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Select the deployment mode of "Security-Optimized". The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview" and select the action set for each category to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002661
- Version
- TIPP-IP-000410
- Vuln IDs
-
- V-242203
- Rule IDs
-
- SV-242203r710152_rule
Checks: C-45478r710150_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Ensure the deployment mode of "Security-Optimized" is selected. The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview" and ensure the action set for each category is set to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon. If the "security-optimized" deployment mode is not configured, this is a finding.
Fix: F-45436r710151_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Select the deployment mode of "Security-Optimized". The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview", and select the action set for each category to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002662
- Version
- TIPP-IP-000420
- Vuln IDs
-
- V-242204
- Rule IDs
-
- SV-242204r710155_rule
Checks: C-45479r710153_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Ensure the deployment mode of "Security-Optimized" is selected. The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview" and ensure the action set for each category is set to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon. If the "security-optimized" deployment mode is not configured, this is a finding.
Fix: F-45437r710154_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Inspection Profiles" and select the organization's profile. 2. If there is not one configured, select "Default". 3. Click "Edit Details". Select the deployment mode of "Security-Optimized". The security-optimized deployment mode ensures all strict DoD vulnerabilities are blocked and alerted upon. 4. Navigate to "Profile Overview", and select the action set for each category to "Recommended". The recommended action set is set to ensure all suspicious and vulnerable traffic is blocked and alerted upon.
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002664
- Version
- TIPP-IP-000430
- Vuln IDs
-
- V-242205
- Rule IDs
-
- SV-242205r710158_rule
Checks: C-45480r710156_chk
1. In the Trend Micro SMS, navigate to "Profiles" and "Shared Settings". 2. Under "Action Sets", if a group email address for the ISSO is not added for both the "Block+Notify" and "Block+Notify+Trace", this is a finding.
Fix: F-45438r710157_fix
1. In the Trend Micro SMS, navigate to "Profiles" and "Shared Settings". 2. Under "Action Sets": a. Select "Block+Notify" and Edit. b. Select Notifications, click "add", and add an email address for the ISSO and the aggregation time in minutes. c. Select "Finish".
- RMF Control
- SI-4
- Severity
- M
- CCI
- CCI-002664
- Version
- TIPP-IP-000440
- Vuln IDs
-
- V-242206
- Rule IDs
-
- SV-242206r710161_rule
Checks: C-45481r710159_chk
The ISSM and ISSO must be registered to receive updates from the TMC site. If not, this is a finding.
Fix: F-45439r710160_fix
1. Navigate to https://tmc.tippingpoint.com/TMC/ 2. Click "Create account". 3. Enter all required data ensuring that the Client ID, Device Certificate Number, and/or Access Code is added. 4. Click "Submit".