background image

 

Installation Guidelines and Preparative Procedures  

Verify Software 

 

Operational User Guidance and Preparative Procedures Supplement for Common Criteria 

9 

The evaluated configuration includes one or more instances of McAfee Agent and VirusScan Enterprise 

and an instance of McAfee ePO.  The following configuration should apply to the evaluated 

configuration: 

All user accounts defined in McAfee ePO must specify Windows authentication. 

McAfee Agent should only be installed by using the McAfee ePO interface. 

Remote viewing of TOE log files on the clients is disabled.   

Only authorized processes may initiate network connections to remote port 25 (SMTP).  The 

Central Administrator configures the list of authorized processes. 

The U.S. Government Protection Profile Anti-Virus Applications for Workstations in Basic 

Robustness Environments requires the TOE to restrict specific management functionality to the 

Central Administrator role.  At least one ePO user must be defined as a Central Administrator.  For 

this TOE, the Central Administrator role is defined as an authorized administrator with Global 

Administrator status. 

Because the 

U.S. Government Protection Profile Anti-Virus Applications for Workstations in Basic 

Robustness Environments

 requires the TOE to restrict specific management functionality to the 

Central Administrator role, the following permissions may never be assigned: 

View audit log. 

View and purge audit log. 

View VSE settings. 

View and change VirusScan Enterprise settings. 

Functionality Not Included in the Evaluation 

The following functionality is not included in the evaluation: 

 

The ability to protect against buffer overflows 

 

The ability to identify spyware 

 

The Scriptscan feature that scans JavaScript and VBScript scripts 

 

The ability to update the TOE (scan engine).  Note that the ability to update the virus 

signatures (DAT file) is included in the evaluation. 

 

The optional Alert Manager product 

Verify Software 

The administrator should follow one of the following points to ensure the proper version of software is 

installed: 

 

The administrator can view McAfee ePO versioning information on the title bar/tab header 

when logged into ePolicy Orchestrator: 

Summary of Contents for EPOLICY ORCHESTRATOR 4.5 -

Page 1: ...Supplement for Common Criteria Operational User Guidance and Preparative Procedures McAfee VirusScan Enterprise 8 8 McAfee ePolicy Orchestrator 4 5 Software...

Page 2: ...tered trademarks herein are the sole property of their respective owners LICENSE INFORMATION License Agreement NOTICE TO ALL USERS CAREFULLY READ THE APPROPRIATE LEGAL AGREEMENT CORRESPONDING TO THE L...

Page 3: ...rocedures 7 Overview 7 Downloading the TOE 7 Evaluated Configuration 8 Functionality Not Included in the Evaluation 9 Verify Software 9 Updating System Software 10 Install Database Capacity Monitor Ex...

Page 4: ...4 Operational User Guidance and Preparative Procedures Supplement for Common Criteria...

Page 5: ...ng the product in accordance with the Common Criteria evaluated configuration The documents listed above in conjunction with this supplement describe how to administer the TOE in a manner that meets t...

Page 6: ...non hostile are authenticated to the internal network and follow all administrator guidance Human users considered to be anyone who interacts with the TOE who are not authorized administrators cannot...

Page 7: ...guration Verify Software Install Database Capacity Monitor Extension Overview Prior to installation the administrator should read and be familiar with the details of all documentation for McAfee Virus...

Page 8: ...appears 4 Click I Agree the ePolicy Orchestrator download page appears containing a list of links 5 Click and download the ePolicy Orchestrator file ePO450P3 Zip 6 Click the Documentation tab 7 Selec...

Page 9: ...inistrator For this TOE the Central Administrator role is defined as an authorized administrator with Global Administrator status 6 Because the U S Government Protection Profile Anti Virus Application...

Page 10: ...te license grant for the evaluated software version Install Database Capacity Monitor Extension The purpose of the feature is to enable the use of automatic responses to alert the administrator of the...

Page 11: ...ng an Automatic Response Step 1 Adjust or Review Database space requirements The user can create a query for systems with less than for example 10GB free of system drive space The user can create a se...

Page 12: ...This server task creates entries in the EPOServerEvents table using the event id of 16081 and contains information pertaining to the audit log entry and server information The presence of the event id...

Page 13: ...13 2 Add the Event ID as a filter and specify 16081 as the value On the Aggregation tab of the Automatic Response builder screen it should be noted that throttling should be used in order to not overl...

Page 14: ...nes and Preparative Procedures Install Database Capacity Monitor Extension 14 Operational User Guidance and Preparative Procedures Supplement for Common Criteria 3 Review settings and save the automat...

Page 15: ...on Inspection The administrator should periodically verify that the evaluated version of software is running Required Password Length When adding other administrator accounts to the TOE the administra...

Reviews: