The organizations written policy must include procedures for how often the whitelist of allowed applications is reviewed.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-213325
MCAC-PO-000110
SV-213325r961479_rule
Medium
Description
Enabling application whitelisting without adequate design and organization-specific requirements will either result in an implementation which is too relaxed or an implementation which causes denial of service to its user community. Documenting the specific requirements and trust model before configuring and deploying the Trellix Application Control software is mandatory.