FireEye – Login banner Details The login banner should be reviewed to ensure it complies with organizational standards. This security hardening control applies to...
FireEye – Management interface is only accessible from specific IP ranges Details The management interface should only be accessible from trusted portions of the network to limit attack opportunities. The appliance...
FireEye – NTP client is synchronized Details An accurate clock is essential for log analysis and correlation with other devices. This check looks at the current...
FireEye – Inline blocking mode configuration Details If you have configured an appliance for inline blocking mode, you may customize blocking actions such as TCP resets,...
FireEye – NTP client uses a custom server Details If no custom NTP servers are specified the appliance will utilize default servers on the Internet which may not...
FireEye – Inline blocking network whitelists Details If you have configured an appliance for inline blocking mode, you may customize the blocking operation with whitelists. A...
FireEye – NTP is enabled Details An accurate clock is essential for log analysis and correlation with other devices. NTP must be enabled to synchronize...
FireEye – Inline blocking signature policy exceptions Details If you have configured an appliance for inline blocking mode, and a blocking event is listed on the Alerts...
FireEye – Remote syslog is enabled Details Security log information could be modified or lost if the host is compromised or fails. Syslog messages should be...
FireEye – Interface configuration Details Interfaces operate in pairs called A, B, etc. Two inline modes of operation are supported: detection mode and blocking...