STIGQter STIGQter: STIG Summary: Forescout Network Access Control Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

Forescout must enforce approved access by employing admissions assessment filters that include, at a minimum, device attributes such as type, IP address, resource group, and/or mission conditions as defined in Forescout System Security Plan (SSP). This is required for compliance with C2C Step 4.

DISA Rule

SV-233309r1146387_rule

Vulnerability Number

V-233309

Group Title

SRG-NET-000015-NAC-000020

Rule Version

FORE-NC-000010

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Use the Forescout Administrator UI to configure the endpoint compliance assessment policies per the SSP. Example only:

1. Log on to Forescout UI.
2. From the Policy tab, select the top most policy.
3. Select Add >> Classification >> Primary Classification, and then click "Next".
4. Give the policy a name, then click "Next".
5. If applicable, select the IP Address Range the policy will apply to, click "Ok", and then click "Next".
6. Select "Finish, then click "Apply".

Check Contents

If DoD is not at C2C Step 4 or higher, this is not a finding.

Use the Forescout Administrator UI to ensure that the endpoint compliance assessment policies have been implemented per the SSP and are functioning correctly.

If Forescout does not have compliance assessment policies configured this is a finding.

Vulnerability Number

V-233309

Documentable

False

Rule Version

FORE-NC-000010

Severity Override Guidance

If DoD is not at C2C Step 4 or higher, this is not a finding.

Use the Forescout Administrator UI to ensure that the endpoint compliance assessment policies have been implemented per the SSP and are functioning correctly.

If Forescout does not have compliance assessment policies configured this is a finding.

Check Content Reference

M

Target Key

5250