STIGQter STIGQter: STIG Summary: Forescout Network Access Control Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

Endpoint policy assessment must proceed after the endpoint attempting access has been identified using an approved identification method such as IP address. This is required for compliance with C2C Step 2.

DISA Rule

SV-233310r1146388_rule

Vulnerability Number

V-233310

Group Title

SRG-NET-000015-NAC-000030

Rule Version

FORE-NC-000020

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Use the Forescout Administrator UI to configure the endpoint compliance assessment policies per the SSP.

1. From the console on the Enterprise Manager console, select the Policy tab.
2. In accordance with the SSP, ensure that the endpoint compliance assessment policies have been configured and are functioning properly.

Check Contents

If DoD is not at C2C Step 2 or higher, this is not a finding.

Use the Forescout Administrator UI to ensure that the endpoint compliance assessment policies have been implemented per the SSP and are functioning correctly.

1. Log on to the Forescout Administrator UI.
2. From the Home screen select the "Policy" tab.
3. Verify that policies exist that assess compliance in accordance with the SSP.

If Forescout does not have compliance assessment policies configured this is a finding.

Vulnerability Number

V-233310

Documentable

False

Rule Version

FORE-NC-000020

Severity Override Guidance

If DoD is not at C2C Step 2 or higher, this is not a finding.

Use the Forescout Administrator UI to ensure that the endpoint compliance assessment policies have been implemented per the SSP and are functioning correctly.

1. Log on to the Forescout Administrator UI.
2. From the Home screen select the "Policy" tab.
3. Verify that policies exist that assess compliance in accordance with the SSP.

If Forescout does not have compliance assessment policies configured this is a finding.

Check Content Reference

M

Target Key

5250