McAfee PASCDE-AB-IA Product Guide - Page 87

Appendix A: Implementing the Security Content Automation Protocol, Statement of FDCC compliance

Page 87 highlights

Appendix A: Implementing the Security Content Automation Protocol McAfee Policy Auditor version 6.0 uses the Security Content Automation Protocol (SCAP) version 1.1. Security content conforming to the SCAP standard can be used by any product supporting the standard and the results can be shared between these products. SCAP is a collection of six open standards developed jointly by various United States government organizations and the private sector. McAfee Policy Auditor uses the Security Content Automation Protocol (SCAP) to perform automated audits, including policy compliance evaluations such as the Federal Information Security Management Act (FISMA). Contents Statement of FDCC compliance Statement of SCAP implementation Statement of CVE implementation Statement of CCE implementation Statement of CPE implementation Statement of CVSS implementation Statement of XCCDF implementation Statement of OVAL implementation Statement of FDCC compliance McAfee asserts that McAfee Policy Auditor version 6.0 does not alter or conflict with the Federal Desktop Core Configuration (FDCC) settings on Microsoft Windows XP and Vista systems. These ports are used by McAfee Policy Auditor version 6.0. Setting Port Agent-to-server communication 80 Agent wake-up communication 8081 Agent broadcast communication 8082 Console-to-application server 8443 communication Sensor-to-server communication 8444 Security threats communication 8801 SQL server TCP 1443 Can be edited No Yes Yes Only during installation Only during installation Only during installation Only during installation McAfee Policy Auditor 6.0 software Product Guide for ePolicy Orchestrator 4.6 87

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98

Appendix A: Implementing the Security Content
Automation Protocol
McAfee Policy Auditor version 6.0 uses the Security Content Automation Protocol (SCAP)
version 1.1. Security content conforming to the SCAP standard can be used by any product
supporting the standard and the results can be shared between these products.
SCAP is a collection of six open standards developed jointly by various United States government
organizations and the private sector.McAfee Policy Auditor uses the Security Content Automation
Protocol (SCAP) to perform automated audits, including policy compliance evaluations such as
the Federal Information Security Management Act (FISMA).
Contents
Statement of FDCC compliance
Statement of SCAP implementation
Statement of CVE implementation
Statement of CCE implementation
Statement of CPE implementation
Statement of CVSS implementation
Statement of XCCDF implementation
Statement of OVAL implementation
Statement of FDCC compliance
McAfee asserts that McAfee Policy Auditor version 6.0 does not alter or conflict with the Federal
Desktop Core Configuration (FDCC) settings on Microsoft Windows XP and Vista systems.
These ports are used by McAfee Policy Auditor version 6.0.
Can be edited
Port
Setting
No
80
Agent-to-server communication
Yes
8081
Agent wake-up communication
Yes
8082
Agent broadcast communication
Only during installation
8443
Console-to-application server
communication
Only during installation
8444
Sensor-to-server communication
Only during installation
8801
Security threats communication
Only during installation
1443
SQL server TCP
87
McAfee Policy Auditor 6.0 software Product Guide for ePolicy Orchestrator 4.6