McAfee PASCDE-AB-IA Product Guide - Page 63

Create and apply a file integrity monitoring policy, Menu | Policy | Policy Catalog

Page 63 highlights

File Integrity Monitoring and entitlement reporting Create and apply a file integrity monitoring policy One aspect of compliance monitoring is knowing which accounts have access to which files. McAfee Policy Auditor monitors these access permissions. • User - User who has access to the file. • Is Group - Whether the User is a group. • Read Data - Whether the User has the ability to read the file. • Write Data - Whether the User has the ability to write to the file. • Execute - Whether the User has the ability to execute the file. • Delete - Whether the User has the ability to delete the file. Create and apply a file integrity monitoring policy Using a file integrity monitoring policy is a two-stage process. First, you must create the policy. Next, you must apply the policy to selected systems in a System Tree group. You can create one policy per group. Tasks Create a file integrity monitoring policy Apply a policy to systems Compare file versions Accept file integrity monitoring events Purge file integrity monitoring events Create a new file integrity monitoring baseline Create a file integrity monitoring policy Create a policy to monitor file integrity, file entitlement, and version changes. Before you begin You must install the McAfee Policy Auditor agent plug-in on all systems that are to be monitored. For instructions on how to do this, see Managing the McAfee Policy Auditor agent plug-in. When adding, editing, or excluding text files, you can use the ? wildcard to represent one character and the * wildcard to represent multiple characters. Task For option definitions, click ? in the interface. 1 Click Menu | Policy | Policy Catalog. 2 From the Product drop-down list, select Policy Auditor Agent 6.0.0. 3 From the Category drop-down list, select File Integrity Monitor. 4 Click Actions | New Policy. The New policy dialog box appears. 5 Provide information about the new policy: Option Category Definition Select File Integrity Monitor. This is selected by default. McAfee Policy Auditor 6.0 software Product Guide for ePolicy Orchestrator 4.6 63

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98

One aspect of compliance monitoring is knowing which accounts have access to which files.
McAfee Policy Auditor monitors these access permissions.
User
User who has access to the file.
Is Group
Whether the User is a group.
Read Data
Whether the User has the ability to read the file.
Write Data
Whether the User has the ability to write to the file.
Execute
Whether the User has the ability to execute the file.
Delete
Whether the User has the ability to delete the file.
Create and apply a file integrity monitoring policy
Using a file integrity monitoring policy is a two-stage process. First, you must create the policy.
Next, you must apply the policy to selected systems in a System Tree group.You can create
one policy per group.
Tasks
Create a file integrity monitoring policy
Apply a policy to systems
Compare file versions
Accept file integrity monitoring events
Purge file integrity monitoring events
Create a new file integrity monitoring baseline
Create a file integrity monitoring policy
Create a policy to monitor file integrity, file entitlement, and version changes.
Before you begin
You must install the McAfeePolicy Auditor agent plug-in on all systems that are to be monitored.
For instructions on how to do this, see
Managing the McAfee Policy Auditor agent plug-in
.
When adding, editing, or excluding text files, you can use the
?
wildcard to represent one
character and the
*
wildcard to represent multiple characters.
Task
For option definitions, click
?
in the interface.
1
Click
Menu | Policy | Policy Catalog
.
2
From the Product drop-down list, select
Policy Auditor Agent 6.0.0
.
3
From the Category drop-down list, select
File Integrity Monitor
.
4
Click
Actions | New Policy
.The New policy dialog box appears.
5
Provide information about the new policy:
Definition
Option
Select File Integrity Monitor.This is selected by default.
Category
File Integrity Monitoring and entitlement reporting
Create and apply a file integrity monitoring policy
63
McAfee Policy Auditor 6.0 software Product Guide for ePolicy Orchestrator 4.6