STIGQter STIGQter: STIG Summary: Forescout Network Device Management Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

Forescout must be configured to use Coordinated Universal Time (UTC).

DISA Rule

SV-230945r1111875_rule

Vulnerability Number

V-230945

Group Title

SRG-APP-000374-NDM-000299

Rule Version

FORE-NM-000170

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove accounts that are not authorized. Do not remove the account of last resort.

1. Log on to the Forescout Administrator UI with admin or operator credentials.
2. From the menu, select Tools >> Options >> CounterAct User Profiles.
3. Select (highlight) the user profile to be reviewed (group or user) and then select "Remove".
4. Remove any applicable external group membership or individual users on the external directory service.

Check Contents

Determine if Forescout records time stamps for log records that can be mapped to UTC. This requirement may be verified by demonstration or configuration review.

Note: Updating time preferences will force Forescout into maintenance mode and the service must be restarted. Use a scheduled outage for planned maintenance and stop Forescout service prior to adjusting time settings.

1. From the CLI run "fstool tz".
2. Type "yes" to change the timezone.
3. Type "2" for GMT offset.
4. Type "0" to enter the offiset (GMT 0 is equal to UTC time).
5. Ensure the Local time and Universal time match and type "yes" to continue.
6. Type "yes" to reboot.

If Forescout does not record time stamps for log records that can be mapped to UTC, this is a finding.

Vulnerability Number

V-230945

Documentable

False

Rule Version

FORE-NM-000170

Severity Override Guidance

Determine if Forescout records time stamps for log records that can be mapped to UTC. This requirement may be verified by demonstration or configuration review.

Note: Updating time preferences will force Forescout into maintenance mode and the service must be restarted. Use a scheduled outage for planned maintenance and stop Forescout service prior to adjusting time settings.

1. From the CLI run "fstool tz".
2. Type "yes" to change the timezone.
3. Type "2" for GMT offset.
4. Type "0" to enter the offiset (GMT 0 is equal to UTC time).
5. Ensure the Local time and Universal time match and type "yes" to continue.
6. Type "yes" to reboot.

If Forescout does not record time stamps for log records that can be mapped to UTC, this is a finding.

Check Content Reference

M

Target Key

5245