McAfee EPOLICY ORCHESTRATOR 4.0.2 - User's Guide

Browse online or download User's Guide for Software McAfee EPOLICY ORCHESTRATOR 4.0.2 -. McAfee EPOLICY ORCHESTRATOR 4.0.2 - Product guide User Manual

  • Download
  • Add to my manuals
  • Print
  • Page
    / 96
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews

Summary of Contents

Page 1 - Product Guide

McAfee Policy Auditor 5.0Product Guide

Page 2

Using this guideThis guide provides basic information on configuring Policy Auditor. For information on configuringthe ePO server, refer to theMcAfee

Page 3 - Contents

Where to find McAfee product informationThe McAfee documentation is designed to provide you with the information you need duringeach phase of product

Page 4

Configuring Policy AuditorPolicy Auditor is configured from the ePO Server. The ePO Server is the center of your managedenvironment and provides a sin

Page 5

benchmarks determine compliance with its rules, but they also return results that can beconverted to a human-readable format.Server setting categories

Page 6

Audit labelPolicy Auditor allows you to set the names used to describe whether an audit has a status ofpass, fail, or unknown. McAfee recommends that

Page 7

What happens when I install new products?When a new extension is installed it might add one or more sections to the permission sets.For example, when

Page 8

PermissionsPermission Set• Issue Management: Create, edit, view and purgeassigned issues• Policy Auditor: View Audits and Assignments• Policy Auditor:

Page 9 - Benchmark Editor

Before you beginYou must have appropriate permissions to perform this task.TaskFor option definitions, click ? on the page displaying the options.1 Go

Page 10 - Using this guide

2 Click edit next to any section for which you want to grant permissions.3 On the Edit Permission Set page that appears, select the appropriate option

Page 11

Complying with SCAPPolicy Auditor uses the Security Content Automation Protocol (SCAP) to perform automatedaudits, including policy compliance evaluat

Page 12 - Configuring Policy Auditor

COPYRIGHTCopyright © 2008 McAfee, Inc. All Rights Reserved.No part of this publication may be reproduced, transmitted, transcribed, stored in a retrie

Page 13 - Server setting categories

Statement of CVE ImplementationMcAfee Policy Auditor 5.0 fully implements and supports the Common Vulnerabilities andExposures (CVE) standard vulnerab

Page 14 - How permission sets work

characteristics. Using CVSS weighted scores can help an organization determine and prioritizeresponses to detected vulnerabilities.Policy Auditor supp

Page 15 - Built-in permission sets

Managing the Policy Auditor Agent Plug-inThe Policy Auditor Agent Plug-in is an extension of the McAfee agent. The extension managesthe schedule for p

Page 16 - Editing server settings

Supported platformsPolicy Auditor 5.0 and the Policy Auditor Agent Plug-in supports the following platforms:NotesOther ProcessorsX64X86OSXWindows 2000

Page 17 - Editing a permission set

Working with the McAfee Policy Auditor AgentPlug-inUse these tasks to manage the installation and uninstallation of the McAfee Policy AuditorPlug-in.T

Page 18 - Deleting a permission set

Deploying the Policy Auditor Agent Plug-inUse this task to deploy the Policy Auditor Agent Plug-in to managed systems on your network.Before you begin

Page 19 - Complying with SCAP

8 Send a manual wake-up call to the appropriate group if you want the task to runimmediately.Determining whether the Agent Plug-in is being deployedUs

Page 20

Before you beginYou must have already installed the Policy Auditor Agent Plug-in on the systems for which youwant to verify communication.TaskFor opti

Page 21

e Set whether to use the local system time or Coordinated Universal Time (UTC) forrunning the task.f For Schedule, select an option from the dropdown

Page 22

3 Select More Actions at the bottom left of the page and select Show Agent Log. A newbrowser window will open that shows the agent log.4 Search the lo

Page 23 - Managing content

ContentsIntroducing McAfee Policy Auditor 5.0. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8Poli

Page 24

Creating and Managing AuditsMcAfee Policy Auditor 5.0 makes it easy to demonstrate and report on compliance with recognizedcorporate and industry secu

Page 25

DefinitionOptionCreate a new audit using the New Audit BuilderNew AuditDelete the selected auditsDeleteCreates an OVAL results file that conforms to t

Page 26

Benchmarks contain rules describing the desired state of a managed system according torecognized standards.Figure 2: Policy TreeRules contain one or m

Page 27 - Wake Up Agents

• Add Group — a group defined in the ePO System Tree• Add Tag — systems that have been tagged in the ePO System Tree, such as server,workstation, or l

Page 28

Benchmark profiles and their impact on managedsystemsAudits have benchmarks assigned to them. Many benchmarks contain profiles, which are namedsets of

Page 29

than 4 days. Blackout windows are set from 8am to 5pm on weekdays. Whiteout windows coverthe remaining period.If the benchmark is scheduled for re-eva

Page 30 - Creating and Managing Audits

The page provides a control that allows you to view the results by system group, systemsubgroup, systems with a specific tag, or even individual syste

Page 31 - Audits and how they work

4 To block out a period of time when audits should not run, click a white square correspondingto your desired day and hour. To allow a period of time

Page 32

TasksSelecting benchmarksDeleting AuditsSelecting benchmarksUse this task to select one or more benchmarks for use in an audit. If a benchmark has pro

Page 33

b Select Criteria, then select one or more Available Properties to add to the ComputerProperties pane. Choose the Comparison and select or type in the

Page 34

Statement of CVSS Implementation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20

Page 35

Editing existing auditsUse these tasks to edit existing audits. Editing audits is useful in a number of situations, forexample:• The groups or systems

Page 36 - Audit exports

Before you beginYou must have appropriate permissions to perform this task.TaskFor option definitions, click ? on the page displaying the options.1 Se

Page 37 - Creating a new audit

TaskFor option definitions, click ? on the page displaying the options.1 Review your new audit. If changes need to be made, click Back until you have

Page 38 - Selecting benchmarks

Scoring AuditsWhen Policy Auditor performs an audit on a managed system, it accepts as input the state ofthe system and any benchmarks in the audit, a

Page 39 - Saving your audit

model is easy to determine and to understand, scores between different managed systems maynot be directly comparable because the maximum score can var

Page 40 - Editing existing audits

Creating and Managing WaiversWaivers provide a way for you to temporarily affect audit scoring for managed systems. Waiversare useful when you have a

Page 41 - Saving your existing audits

How waivers workWaivers temporarily affect audit scoring for managed systems. Policy Auditor provides threetypes of waivers with each one exhibiting d

Page 42 - Deleting Audits

DescriptionColumnThe date when a waiver takes effectStart DateA waiver may have a status of Requested, Upcoming,In-effect, or Expired.StatusThe system

Page 43 - Scoring Audits

• Example of scoring impact:A benchmark has 5 rules. An audit is run on a system and 4 rules pass and 1 fail, resultingin a score of 80%. If the syste

Page 44 - Changing the scoring model

system-based only and, when you request a waiver, Policy Auditor does not allow you to assigna benchmark and rule.Waivers can only be applied to a sin

Page 45 - Creating and Managing Waivers

Flat unweighted scoring model. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44Absolute

Page 46 - Waivers catalog

DescriptionFiltergroup of the System Tree . When you select This Groupand all Subgroups, Policy Auditor shows waivers in theselected group of the Syst

Page 47 - Types of waivers

As of today's date of 10/01/2008, Waiver A and Waiver B both have astatus of Upcoming. Use the calendar control to reset the As of date to12/02/2

Page 48 - Waiver status

2 Click New Waiver. The Waiver Request page appears.3 Name the waiver then select the type of waiver that you wish to create from the WaiverType drop-

Page 49 - Filtering waivers

Expiring waiversUse this task to make a waiver expire.Before you beginYou must have waiver grantor permissions to perform this task.TaskFor option def

Page 50 - Filtering waivers by status

Managing Issues and TicketsThe Issue extension allows you to create, modify, assign, and track issues. You can also addtickets to issues for tracking

Page 51 - Requesting waivers

How issues are managedHow issues are managed and their life cycles are defined by the user and the installed productextensions. An issue's state,

Page 52 - Granting waivers

Why ticketed issues should not be edited manuallyEditing a ticketed issue manually breaks the relationship between the ticketed issue and theticket. T

Page 53 - Deleting waivers

• If the registered server for the ticketing server is deleted, the system changes the state ofeach ticketed issue to Assigned or to New if the ticket

Page 54 - Managing Issues and Tickets

Sample mappingsWhen you register your ticketing server, you must also configure the field mappings for issuesand tickets. These sample field mappings

Page 55 - Tickets and how they work

Operation: Identity•• Source field: URLMap Ticket back to Issue Status fieldNOTE: Because this section only maps the ticket's state/status, you a

Page 56 - How tickets are reopened

Working with issues. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Page 57 - Required fields for mapping

• Source field: Activity Log• Ticket field: Type the name or ID for any open text field• Operation: Identity• Source field: URLMap Ticket back to Issu

Page 58 - Sample mappings

2 In the Action panel, select an issue type, then click OK. This choice determines the optionsavailable on the New Issue page.3 Type a name and descri

Page 59

15 Accept the default values for state, priority, severity, and resolution, or select differentvalues.16 Type the name of the user to whom you want th

Page 60 - Working with issues

Editing issuesUse this task to edit an issue. An issue can be edited in a similar way when viewing its details.CAUTION: Editing a ticketed issue break

Page 61

TaskFor option definitions, click ? on the page displaying the options.1 Go to Automation | Server Tasks, then click New Task. The Description page of

Page 62 - Adding comments to issues

3 Select the General tab.4 Under Service status, click Stop. The server is now stopped.5 Copy the required files for your ticketing server, then repea

Page 63 - Purging closed issues

• arrpc51.dll• arutl51.dll• If using the Remedy 7.0 API files:• arapi70.dll• arjni70.dll• arrpc70.dll• arutiljni70.dll• arutl70.dll• arxmlutil70.dll•

Page 64

Installing the ticketing server extensionsUse this task to install ticketing server extensions.Before you begin• Copy the files required for the ticke

Page 65 - Copying the Remedy files

• On the system running Service Desk 4.5, add the name of that system as a DNS suffixin the IP settings, then reboot the Service Desk 4.5 system.Figur

Page 66

• Know which fields from the ticketing server need to be mapped.TasksMapping issues to ticketsMapping tickets back to issue statusMapping issues to ti

Page 67

PA: Benchmark Rules. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 83PA:

Page 68

Mapping tickets back to issue statusUse this task to configure the field mapping from the ticket back to the issue's status (state)field.NOTE: Be

Page 69 - Mapping issues to tickets

Before you begin• Make sure the upgraded version of the ticketing server is running.TaskCAUTION: If the server task, which synchronizes ticketed issue

Page 70

Task1 Go to Reporting | Issues, select the checkbox next to each issue, then click Add ticket.2 In the Action panel, click OK to add a ticket to each

Page 71 - Working with tickets

Querying the DatabasePolicy Auditor ships with its own querying and reporting capabilities. These are highlycustomizable and provide flexibility and e

Page 72 - Synchronizing ticketed issues

Exported resultsQuery results can be exported to four different formats. Exported results are historical data andare not refreshed like when using que

Page 73 - Querying the Database

Query BuilderePolicy Orchestrator provides an easy, four-step builder with which to create and edit customqueries. With the wizard you can configure w

Page 74 - Query permissions

Table columnsSpecify columns for the table. If you select Table as the primary display of the data, thisconfigures that table. If you selected a type

Page 75 - Query Builder

Creating a Data Roll Up server taskRegistering ePO serversUse this task to register each ePO server with the reporting server that you want to include

Page 76 - Multi-server roll-up querying

Working with queriesUse these tasks to create, use, and manage queries.TasksCreating custom queriesRunning an existing queryRunning a query on a sched

Page 77 - Registering ePO servers

Running an existing queryUse this task to run an existing query from the Queries page.TaskFor option definitions, click ? on the page displaying the o

Page 78 - Working with queries

Introducing McAfee Policy Auditor 5.0McAfee Policy Auditor evaluates the status of managed systems relative to audits that containbenchmarks. Benchmar

Page 79 - Running a query on a schedule

• Move To — Moves all systems in the query results to a group in the System Tree. Thisoption is only valid for queries that result in a table of syste

Page 80

Making personal queries publicUse this task to make personal queries public. All users with permissions to public queries haveaccess to any personal q

Page 81 - Duplicating queries

2 Click Export, then OK in the Action panel. The File Download dialog box appears.3 Click Save, select the desired location for the XML file, then cli

Page 82 - Importing queries

Default queries and what they displayPolicy Auditor ships with a number of default queries that can be used for some of your mostcommon needs. Each of

Page 83 - PA: Check Catalog List

DefinitionOptionExport the check in a ZIP formatExportRemove labels from checkRemove LabelsPA: Check Catalog Usage ListUse this page to view a list of

Page 84 - PA: Systems by Audit

Before you beginThis query and its results depend on the Generate Compliance Event server task. Schedule thisserver task to run at a regular interval.

Page 85

Assessing Your Environment With DashboardsDashboards allow you to keep a constant eye on your environment. Dashboards are collectionsof monitors. Moni

Page 86 - Dashboards and how they work

• McAfee Links — Hyperlinks to McAfee sites, including ePolicy Orchestrator Support, AvertLabs WebImmune, and Avert Labs Threat Library.Setting up das

Page 87

Working with DashboardsUse these tasks to create and manage dashboards.TasksCreating dashboardsMaking a dashboard activeSelecting all active dashboard

Page 88 - Working with Dashboards

TaskFor option definitions, click ? on the page displaying them.1 Go to Dashboards, click Options, then select Manage Dashboards. The ManageDashboards

Page 89 - Making a dashboard public

ContentsPolicy Auditor components and what they doWhere to find McAfee product informationPolicy Auditor components and what they doMcAfee Policy Audi

Page 90

TaskFor option definitions, click ? on the page displaying the options.1 Go to Dashboards, then select Manage Dashboards from the Options drop-down li

Page 91

IndexAabsolute scoring model 44agent plug-inoverview 22responsibilities 22audience 10auditcreate 38audit benchmarks panebenchmark ID 35fail 35pass 35p

Page 92

CVE Implementation 20CVSS Implementation 20Ddashboardsactive set 89chart-based queries and 86configuring access and behavior 87configuring refresh fre

Page 93 - (continued)

permissions(continued)to dashboards 87policy auditoragent plug-in responsibilities 22Policy Auditoragent plug-in 9agent plug-in overview 22audience 10

Page 94

server tasksscheduling a query 79serversimporting and exporting queries 81registering, for queries 77roll-up queries 77servertasksData Roll-Up 77Servi

Page 95

waivers(continued)exemption, effect on audit results 47exemption, effect on scoring 47expired 48, 50, 53expires 46, 51expires date 48expires date, con

Page 96

McAfee Policy Auditor 5.0 Product Guide96Index

Comments to this Manuals

No comments