STIGQter STIGQter: STIG Summary: Forescout Network Device Management Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

Forescout must generate log records showing starting and ending time for administrator access to the system.

DISA Rule

SV-230941r615886_rule

Vulnerability Number

V-230941

Group Title

SRG-APP-000505-NDM-000322

Rule Version

FORE-NM-000130

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the syslog trigger.

1. Log on to Forescout Administrator UI with admin or operator credentials.
2. From the menu, select Tools >> Options >> Modules >> Syslog >> Syslog Triggers.
3. Under User Operations, check "Include user operations".

Check Contents

Verify the syslog trigger is configured.

1. Log on to Forescout Administrator UI with admin or operator credentials.
2. From the menu, select Tools >> Options >> Modules >> Syslog >> Syslog Triggers.
3. Under User Operations, verify "Include user operations" is checked.

If Forescout does not generate log records showing starting and ending time for administrator access to the system, this is a finding.

Vulnerability Number

V-230941

Documentable

False

Rule Version

FORE-NM-000130

Severity Override Guidance

Verify the syslog trigger is configured.

1. Log on to Forescout Administrator UI with admin or operator credentials.
2. From the menu, select Tools >> Options >> Modules >> Syslog >> Syslog Triggers.
3. Under User Operations, verify "Include user operations" is checked.

If Forescout does not generate log records showing starting and ending time for administrator access to the system, this is a finding.

Check Content Reference

M

Target Key

5245

Comments