Changes occur nearly every second in the typical network. These changes most commonly include those made to group memberships, which ports are open, software patches, and other categories. That is precisely why it is so important to remain compliant with standards that regulate change monitoring, such as North American Energy Reliability Corporation Critical Infrastructure Protection (NERC CIP).
Many of the most popular cybersecurity compliance frameworks require the creation of allowlists for installed software, network ports, network services, local users, local shares, and persistent routes. This includes the National Institute of Standards and Technology (NIST) Cybersecurity Framework, the Payment Card Industry Data Security Standard (PCI DSS), and NERC CIP, to name a few. Maintaining compliance with these policy frameworks requires proof that unauthorized changes are detected and remediated quickly.
Product Overview
Fortra’s Tripwire Allowlisting ensures the compliance and security of your network by monitoring the system against lists of allowed configurations. Invalid changes to the monitored items are detected and reported so they can be returned to a compliant state.
Tripwire Allowlisting can then generate audit reports detailing both authorized and unauthorized configurations. To improve audit efficiency, the application also permits the justification for the approved item to be included in the audit report. To reduce the false positive rate of reporting, Tripwire Allowlisting enables you to define system settings that are required versus permitted. Violations are flagged if any entries that are not explicitly permitted are present. Expanded capabilities are provided to specify specific software versions and password age for local users to further refine your allowlist entries.
Key Benefits
Beyond remaining compliant with security frameworks, thoroughly securing your network is impossible if your change detection software cannot rapidly detect changes — especially if they are quickly returned to a compliant state. For these reasons, Tripwire Allowlisting provides the following:
Automated monitoring
Allows users to manage allowlists for open ports, routes, services, shares, software, and users on the systems in their environment
Automatically compares items such as open ports, group memberships, etc. to the allowed lists and makes note of any unauthorized differences
Monitors drift from known good configuration of ports, services, software, and users
Automates Compliance for key NERC CIP requirements, including CIP-007 and CIP-010
Verifies only approved accounts exist on systems codified in an authorized user allowlist
Rapid allowlist change detection
- Can be scheduled to monitor allowlist items for change as often as desired
Secure, user-friendly interface
Easy-to-operate user interface is integrated into the Tripwire Console, where allowed items can be managed as individual objects rather than as lines in a CSV file
You can determine which users are able to access Tripwire Allowlisting and what level of access they should have
Authentication can be integrated with Active Directory
Conduct Audits Efficiently
Although automated compliance monitoring will help your organization secure your network, this is not the same as passing an audit to ensure compliance with the same cybersecurity frameworks. These frameworks exist to protect your organization as well as the customers you serve, which is precisely why staying compliant and passing audits is so important. A failed audit implies negligence on an organization’s behalf and can result in extensive liability should a breach occur. Additionally, the penalties for failing an audit are costly, possibly resulting in multi-million-dollar fines.
Automate Report Generation
When a system is examined, a comprehensive report of authorized and unauthorized settings can be generated by Tripwire Allowlisting that contains the justification information. This report enumerates the settings that are out of compliance and can be configured to provide justification for why the change was allowed. This provides an automatic audit trail of changes, waivers, justifications, as well as unauthorized changes, as they happen. This process is fully customizable to each organization and its individual compliance needs.
Types of Reports
Tripwire Allowlisting helps ensure the accurate creation of three kinds of reports and alerting, classified as follows:
Evidence reporting: Audit justification for individual configurations observed
Security alerting: Overview of compliance with internal security controls and exceptions to them
Compliance reporting: Audit summary of all compliance controls and adherence to them
Use Cases
Users and Passwords: Monitor Local Users and the ability to monitor password age and alert when that age reaches or exceeds a set threshold
Reports: Reports are generated to support two use cases: evidence reporting and alerting for daily maintenance of compliance
Services: Once the user has supplied information about normal or expected services on a system or class of systems, Tripwire Allowlisting will alert on new, unexpected services
Achieve Compliance Standards
Tripwire is used to monitor a wide range of functions. Tripwire Allowlisting takes that tool and tailors it to the specific needs created by NERC CIP and other NIST CF-derived frameworks. The process of creating automated reports can be customized to each organization and its individual compliance needs.
PCI DSS
Tripwire delivers continuous and unmatched PCI compliance through our unique integration of policy management, FIM, vulnerability assessment, and log intelligence. Tripwire Allowlisting specifically addresses PCI v4.0 Requirement 1.2.5 (v3.2.1 Requirement 1.1.6), which relates to the documentation and business justification for use of all services, protocols, and allowed ports.
NERC CIP
Tripwire Allowlisting lends its power — in conjunction with Tripwire, Fortra VM, and Tripwire LogCenter — to help you address the requirements contained in these NERC CIPv6 standards:
CIP-007 R1: Ports and Services: The solution can monitor ports and services and compare current state against a tailored set of customer-specific approved ports and services, alerting when monitoring detects a variance.
CIP-007 R2: Security Patch Management: The app can identify software versions and installed patches and compare current state against a tailored set of Patch Management customer-specific approved software versions and patches, alerting when there is a variance on specific BCAs.
CIP-007 R5.2: System Access Controls: The app can verify only approved accounts exist on systems, as codified in an authorized user allowlist.
CIP-004: Access Management & Access Revocation Programs: The app can verify that only approved accounts exist on systems, as codified in an authorized user allowlist.
CIP-010 R1: Configuration Change Management: Tripwire can monitor all the details required for the CIP baseline, including security configuration details. Any change to the baseline can be reported on for daily compliance activities, as well as for meeting audit requests.
Summary
Tripwire Allowlisting directly addresses your team’s need for a high quality, time- and cost-saving change monitoring application. The application’s user-friendly interface and rapid change detection ensures your organization will be able to easily define and update your allowlists while efficiently tracking any invalid changes made against them. Aside from securing your network, the Tripwire Allowlisting’s automated report generation will save you time preparing for audits and money by reducing findings from those audits.
Let us take you through a demo of Tripwire Allowlisting and answer any of your questions.