Revision 1.2

Nov 26, 2024
Miscellaneous
  • Metadata updated.
  • See also link updated.
Added
  • DISA_STIG_Palo_Alto_Networks_IDPS_v3r1.audit from DISA Palo Alto Networks IDPS v3r1 STIG
  • PANW-IP-000001 - The Palo Alto Networks security platform must enable Antivirus, Anti-spyware, and Vulnerability Protection for all authorized traffic
  • PANW-IP-000020 - The Palo Alto Networks security platform must detect and deny any prohibited mobile or otherwise malicious code at the enclave boundary
  • PANW-IP-000026 - The Palo Alto Networks security platform must detect and drop any prohibited mobile or otherwise malicious code at internal boundaries
  • PANW-IP-000028 - The Palo Alto Networks security platform must send an immediate (within seconds) alert to, at a minimum, the SA when malicious code is detected.
  • PANW-IP-000041 - The Palo Alto Networks security platform must protect against or limit the effects of known and unknown types of denial-of-service (DoS) attacks by employing rate-based attack prevention behavior analysis (traffic thresholds)
Removed
  • DISA_STIG_Palo_Alto_IDPS_v3r1.audit from DISA Palo Alto Networks IDPS v3r1 STIG
  • PANW-IP-000001 - The Palo Alto Networks security platform must enable Antivirus, Anti-spyware, and Vulnerability Protection for all authorized traffic - Antivirus Profiles
  • PANW-IP-000001 - The Palo Alto Networks security platform must enable Antivirus, Anti-spyware, and Vulnerability Protection for all authorized traffic - Antivirus Services
  • PANW-IP-000020 - The Palo Alto Networks security platform must detect and deny any prohibited mobile or otherwise malicious code at the enclave boundary - antivirus rules
  • PANW-IP-000020 - The Palo Alto Networks security platform must detect and deny any prohibited mobile or otherwise malicious code at the enclave boundary - security rules
  • PANW-IP-000026 - The Palo Alto Networks security platform must detect and drop any prohibited mobile or otherwise malicious code at internal boundaries - Antivirus Profiles
  • PANW-IP-000026 - The Palo Alto Networks security platform must detect and drop any prohibited mobile or otherwise malicious code at internal boundaries - Antivirus Services
  • PANW-IP-000028 - The Palo Alto Networks security platform must send an immediate (within seconds) alert to, at a minimum, the SA when malicious code is detected - within seconds alert when malicious code is detected.
  • PANW-IP-000041 - The Palo Alto Networks security platform must protect against or limit the effects of known and unknown types of denial-of-service (DoS) attacks by employing rate-based attack prevention behavior analysis (traffic thresholds) - DoS Protection Object
  • PANW-IP-000041 - The Palo Alto Networks security platform must protect against or limit the effects of known and unknown types of denial-of-service (DoS) attacks by employing rate-based attack prevention behavior analysis (traffic thresholds) - DoS Protection Policy