STIGQter STIGQter: STIG Summary: Forescout Network Access Control Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

If a device requesting access fails Forescout policy assessment, Forescout must communicate with other components and the switch to either terminate the session or isolate the device from the trusted network for remediation. This is required for compliance with C2C Step 3.

DISA Rule

SV-233312r1146390_rule

Vulnerability Number

V-233312

Group Title

SRG-NET-000015-NAC-000060

Rule Version

FORE-NC-000040

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Use the Forescout Administrator UI to configure policies according to the SSP to filter assessed devices based on risk. Ensure the policies remediate or segment the at-risk devices according to the SSP.

1. In the Forescout UI, go to the Policy Tab >> Compliance or Control Policies.
2. Select a policy, then click “Edit”.
3. Configure the Compliance Policies to include any of the following actions:
- Terminate the connection and place the device on a denylist to prevent future connection attempts until action is taken to remove the device from the denylist.
- Redirect traffic from the remote endpoint to the automated remediation subnet for connection to the remediation server or segment the endpoint to a remediation VLAN. Use of ACLs or a VLAN solution is acceptable.
- Allow the device access to limited network services such as public web servers in the protected DMZ (must be approved by the AO).
- Allow the device and user full entry into the protected networks, but flag it for future remediation. With this option, an automated reminder must be used to inform the user of the remediation status.

Check Contents

If DOD is not at C2C Step 3 or higher, this is not a finding.

Use the Forescout Administrator UI to verify that policies are configured to filter the policy assessment devices based on risk and are remediated or isolated according to the SSP.

1. In the Forescout UI, go to the Policy Tab >> Compliance or Control Policies.
2. Verify the action within Compliance Policies is configured with one of the following actions:
- Terminate the connection and place the device on a denylist to prevent future connection attempts until action is taken to remove the device from the denylist.
- Redirect traffic from the remote endpoint to the automated remediation subnet for connection to the remediation server or segment the endpoint to a remediation VLAN. Use of ACLs or a VLAN solution is acceptable.
- Allow the device access to limited network services such as public web servers in the protected DMZ (must be approved by the authorizing official [AO]).
- Allow the device and user full entry into the protected networks, but flag it for future remediation. With this option, an automated reminder should be used to inform the user of the remediation status.

If Forescout does not communicate with the remote access gateway to implement a policy to either terminate the session or isolate the device from the trusted network this is a finding.

Vulnerability Number

V-233312

Documentable

False

Rule Version

FORE-NC-000040

Severity Override Guidance

If DOD is not at C2C Step 3 or higher, this is not a finding.

Use the Forescout Administrator UI to verify that policies are configured to filter the policy assessment devices based on risk and are remediated or isolated according to the SSP.

1. In the Forescout UI, go to the Policy Tab >> Compliance or Control Policies.
2. Verify the action within Compliance Policies is configured with one of the following actions:
- Terminate the connection and place the device on a denylist to prevent future connection attempts until action is taken to remove the device from the denylist.
- Redirect traffic from the remote endpoint to the automated remediation subnet for connection to the remediation server or segment the endpoint to a remediation VLAN. Use of ACLs or a VLAN solution is acceptable.
- Allow the device access to limited network services such as public web servers in the protected DMZ (must be approved by the authorizing official [AO]).
- Allow the device and user full entry into the protected networks, but flag it for future remediation. With this option, an automated reminder should be used to inform the user of the remediation status.

If Forescout does not communicate with the remote access gateway to implement a policy to either terminate the session or isolate the device from the trusted network this is a finding.

Check Content Reference

M

Target Key

5250