
employing ePolicy Orchestrator authentication only. McAfee is recommends that the network
IT administrator assign passwords that meet the following requirements:
• Must be at least 10 characters in length.
• Must contain at least three of the following four character groups:
• English uppercase characters (A-Z).
• English lowercase characters (a-z).
• Numerals (0-9).
• Non-alphanumeric characters, such as !, $, #, %.
User IDs and passwords should be unique. No two users should have the same password. In
addition, the User ID used to access ePolicy Orchestrator should be different from any other
User ID required for related ePolicy Orchestrator functionality such as SQL administration or
creation of distributed repositories.
Administrators must ensure that all user names and passwords are protected by the users in a
manner which is consistent with IT security.
Intrusion prevention system
McAfee Host Intrusion Prevention is a preemptive approach to host and network security used
to identify and quickly respond to potential threats. Host Intrusion Prevention monitors individual
host and network traffic. However, because an attacker might carry out an attack immediately
after gaining access, Host Intrusion Prevention can also take immediate action as preset by the
network administrator.
Timestamp
ePolicy Orchestrator uses either a
datetime
or
smalldatetime
data type, as appropriate, to record
the events and triggers to automatically update the timestamp when any modification takes
place. Many tables have a
datetime
or
smalldatetime
data type to indicate when a row was
created, and are linked to other tables to preserve the date and time of all modifications.
Email alarm notifications of storage space exhaustion
The ePolicy Orchestrator notification feature transmits alerts to designated email recipients.
The administrator must set up four Notifications that require configuration in order to meet the
“alarm” requirements of FAU_STG.4.1 and IDS_STG.2.1
• Notification that storage space for new records in the ePOAuditEvent table in the SQL Server
database is exhausted.
• Purging of the oldest 20% of the records in the ePOAuditEvent table completed successfully.
• Purging of the oldest 20% of the records in the ePOAuditEvent table failed.
• Notification that storage space for new records in the ENT_IPSEvent table in the SQL Server
database is exhausted. When this notification is received, the administrator should purge
the database.
The appropriate
ePolicy Orchestrator Product Guide
provides information about purging and
archiving the database.
System Requirements
Common Criteria considerations
McAfee Policy Auditor 5.2.0 Installation Guide16
Commenti su questo manuale