STIGQter STIGQter: STIG Summary: Forescout Network Device Management Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

Forescout must support organizational requirements to conduct backups of information system documentation, including security-related documentation, when changes occur or weekly, whichever is sooner.

DISA Rule

SV-230957r616550_rule

Vulnerability Number

V-230957

Group Title

SRG-APP-000516-NDM-000341

Rule Version

FORE-NM-000300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Forescout to conduct backups.

Setup a backup server.
1. Open the Forescout Console and select Tools >> Advanced >> Backup >> Backup Server.
2. Click "SCP" or "SFTP" for the transfer protocol.
3. Add the IP address of the backup destination server.
4. Add the directory to receive the file.
5. Add PKI key (preferred) or add username and DoD compliant password for the backup account to be used.
6. Enable "Authenticate Destination Sever".
7. Test the file transfer.
8. Click "Apply".

Generate a backup job.
1. Click the System Backup tab.
2. Select "Enable System Backup".
3. Under Backup Schedule, add a "Generate backup at" and enter a time to run the backup in accordance with site procedures.
4. Select "Weekly" for Recurrence Pattern.

When changes to the configuration occur, the admin must immediately create a new backup by clicking "Backup Now" on the Backup screen.

Check Contents

Check Forescout to determine if the network device is configured to conduct backups.

1. Open the Forescout Console and select Tools >> Advanced >> Backup.
2. On the “System Backup” tab, verify the "Enable System Backup" radio button is selected.
3. Verify the Backup schedule is selected to at least "weekly".

If Forescout does not support organizational requirements to conduct backups of information system documentation, including security-related documentation when changes occur or weekly, whichever is sooner, this is a finding.

Vulnerability Number

V-230957

Documentable

False

Rule Version

FORE-NM-000300

Severity Override Guidance

Check Forescout to determine if the network device is configured to conduct backups.

1. Open the Forescout Console and select Tools >> Advanced >> Backup.
2. On the “System Backup” tab, verify the "Enable System Backup" radio button is selected.
3. Verify the Backup schedule is selected to at least "weekly".

If Forescout does not support organizational requirements to conduct backups of information system documentation, including security-related documentation when changes occur or weekly, whichever is sooner, this is a finding.

Check Content Reference

M

Target Key

5245

Comments