McAfee PASCDE-AB-IA Product Guide - Page 93

Partnership NIAP Common Criteria Validation Scheme CCEVS are directed to assign

Page 93 highlights

Appendix B: Common Criteria requirements Administrators who must adhere to the requirements of the National Information Assurance Partnership (NIAP) Common Criteria Validation Scheme (CCEVS) are directed to assign passwords employing ePolicy Orchestrator software authentication only. McAfee recommends that the network IT administrator assign passwords that meet the following requirements: • Must be at least 10 characters in length. • Must contain at least three of the following four character groups: • English uppercase characters (A-Z). • English lowercase characters (a-z). • Numerals (0-9). • Non-alphanumeric characters, such as !, $, #, %. User IDs and passwords should be unique. No two users should have the same password. In addition, the User ID used to access ePolicy Orchestrator software should be different from any other User ID required for related ePolicy Orchestrator software functionality such as SQL administration or creation of distributed repositories. Administrators must ensure that all user names and passwords are protected by the users in a manner which is consistent with IT security. Intrusion prevention system McAfee Host Intrusion Prevention System software is a preemptive approach to host and network security used to identify and quickly respond to potential threats. McAfee Host Intrusion Prevention System monitors individual host and network traffic. However, because an attacker might carry out an attack immediately after gaining access, McAfee Host Intrusion Prevention System can also take immediate action as preset by the network administrator. Timestamp ePolicy Orchestrator software uses either a datetime or smalldatetime data type, as appropriate, to record the events and triggers to automatically update the timestamp when any modification takes place. Many tables have a datetime or smalldatetime data type to indicate when a row was created, and are linked to other tables to preserve the date and time of all modifications. Email alarm notifications of storage space exhaustion The ePolicy Orchestrator software notification feature transmits alerts to designated email recipients. The administrator must set up four Notifications that require configuration in order to meet the "alarm" requirements of FAU_STG.4.1 and IDS_STG.2.1 • Notification that storage space for new records in the ePOAuditEvent table in the SQL Server database is exhausted. • Purging of the oldest 20% of the records in the ePOAuditEvent table completed successfully. • Purging of the oldest 20% of the records in the ePOAuditEvent table failed. • Notification that storage space for new records in the ENT_IPSEvent table in the SQL Server database is exhausted. When this notification is received, the administrator should purge the database. The appropriate version of the ePolicy Orchestrator software Product Guide provides information about purging and archiving the database. McAfee Policy Auditor 6.0 software Product Guide for ePolicy Orchestrator 4.6 93

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98

Administrators who must adhere to the requirements of the National Information Assurance
Partnership (NIAP) Common Criteria Validation Scheme (CCEVS) are directed to assign
passwords employing ePolicy Orchestrator software authentication only.McAfee recommends
that the network IT administrator assign passwords that meet the following requirements:
Must be at least 10 characters in length.
Must contain at least three of the following four character groups:
English uppercase characters (A-Z).
English lowercase characters (a-z).
Numerals (0-9).
Non-alphanumeric characters, such as !, $, #, %.
User IDs and passwords should be unique. No two users should have the same password. In
addition, the User ID used to access ePolicy Orchestrator software should be different from any
other User ID required for related ePolicy Orchestrator software functionality such as SQL
administration or creation of distributed repositories.
Administrators must ensure that all user names and passwords are protected by the users in
a manner which is consistent with IT security.
Intrusion prevention system
McAfee Host Intrusion Prevention System software is a preemptive approach to host and network
security used to identify and quickly respond to potential threats. McAfee Host Intrusion
Prevention System monitors individual host and network traffic. However, because an attacker
might carry out an attack immediately after gaining access, McAfee Host Intrusion Prevention
System can also take immediate action as preset by the network administrator.
Timestamp
ePolicy Orchestrator software uses either a
datetime
or
smalldatetime
data type, as appropriate,
to record the events and triggers to automatically update the timestamp when any modification
takes place. Many tables have a
datetime
or
smalldatetime
data type to indicate when a row
was created, and are linked to other tables to preserve the date and time of all modifications.
Email alarm notifications of storage space exhaustion
The ePolicy Orchestrator software notification feature transmits alerts to designated email
recipients.The administrator must set up four Notifications that require configuration in order
to meet the
alarm
requirements of FAU_STG.4.1 and IDS_STG.2.1
Notification that storage space for new records in the ePOAuditEvent table in the SQL Server
database is exhausted.
Purging of the oldest 20% of the records in the ePOAuditEvent table completed successfully.
Purging of the oldest 20% of the records in the ePOAuditEvent table failed.
Notification that storage space for new records in the ENT_IPSEvent table in the SQL Server
database is exhausted. When this notification is received, the administrator should purge
the database.
The appropriate version of the
ePolicy Orchestrator software Product Guide
provides information
about purging and archiving the database.
Appendix B: Common Criteria requirements
93
McAfee Policy Auditor 6.0 software Product Guide for ePolicy Orchestrator 4.6