STIGQter STIGQter: STIG Summary: Forescout Network Device Management Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

Forescout must be configured to use Coordinated Universal Time (UTC).

DISA Rule

SV-230945r615886_rule

Vulnerability Number

V-230945

Group Title

SRG-APP-000374-NDM-000299

Rule Version

FORE-NM-000170

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Forescout to record time stamps for log records that can be mapped to UTC.

Note: Updating time preferences will force Forescout into maintenance mode and the service must be restarted. Use a scheduled outage for planned maintenance and stop Forescout service prior to adjusting time settings.

1. Type the following command at the prompt using the IP address of the required NTP server:
fstool ntp <ip address>
2. Ensure the date references accurate time and the time zone points to UTC next to the year.

Check Contents

Determine if Forescout records time stamps for log records that can be mapped to UTC. This requirement may be verified by demonstration or configuration review.

Verify by connecting to the appliance via SSH using standard user/operator privilege.

1. Type "date" at the command prompt.
2. Verify the date references accurate time and "UTC" shows just before the year.

If Forescout does not record time stamps for log records that can be mapped to UTC, this is a finding.

Vulnerability Number

V-230945

Documentable

False

Rule Version

FORE-NM-000170

Severity Override Guidance

Determine if Forescout records time stamps for log records that can be mapped to UTC. This requirement may be verified by demonstration or configuration review.

Verify by connecting to the appliance via SSH using standard user/operator privilege.

1. Type "date" at the command prompt.
2. Verify the date references accurate time and "UTC" shows just before the year.

If Forescout does not record time stamps for log records that can be mapped to UTC, this is a finding.

Check Content Reference

M

Target Key

5245

Comments