STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must log all user activity.

DISA Rule

SV-234171r960864_rule

Vulnerability Number

V-234171

Group Title

SRG-APP-000080-NDM-000220

Rule Version

FGFW-ND-000060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the FortiGate GUI with Super-Admin privilege.
1. Click Log and Report.
2. Click Log Settings.
3. Scroll to Log Settings.
4. For Event Logging, select ALL or Customize.
5. If Customize is selected, ensure to configure, at least, System activity event.
6. Click Apply.

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege:
To verify that logging is enabled:
1. Click Log and Report.
2. Click Log Settings.
3. Scroll down to Log Settings and ensure that Event Logging is set to "All" or "Customize" with System activity events checked.

If Event Logging is not set to ALL or Customize with System activity event checked, this is a finding.

Vulnerability Number

V-234171

Documentable

False

Rule Version

FGFW-ND-000060

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege:
To verify that logging is enabled:
1. Click Log and Report.
2. Click Log Settings.
3. Scroll down to Log Settings and ensure that Event Logging is set to "All" or "Customize" with System activity events checked.

If Event Logging is not set to ALL or Customize with System activity event checked, this is a finding.

Check Content Reference

M

Target Key

5260