STIGQter STIGQter: STIG Summary: Dragos Platform 2.x Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 01 Apr 2026:

The Dragos Platform must alert the information system security officer (ISSO), information system security manager (ISSM), and other individuals designated by the local organization when events are detected that indicate a compromise or potential for compromise.

DISA Rule

SV-271070r1107133_rule

Vulnerability Number

V-271070

Group Title

SRG-APP-000471

Rule Version

DRAG-OT-002120

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Configure Servers.
If using Syslog Server:
Create a Syslog server on a third-party device.
The steps may vary depending on the chosen Syslog server software. Refer to 2.3.x Dragos Platform Syslog Integration Guide in the Customer Portal for additional help.

Create a syslog server output in the Dragos UI.
Navigate to Admin >> Integrations.
Click "LAUNCH" in the Syslog section.
Click "ADD NEW SERVER".
Enter third-party server information and click "NEXT".
Input Message Template.
Click "SAVE".


2. Creating System Rules:
Navigate to Notification >> RULES Tab.
Click "NEW RULE".
Fill in Name and Processing Order.

Create two Attributes.
Click "ADD ATTRIBUTE" in the "If ANY of the following" block:
Type = "Notification Type"
Select Operation = "Equals"
Select Value = "System"

Click "ADD ATTRIBUTE" in the "If ANY of the following" block:
Type = "Notification Type"
Select Operation = "Equals"
Select Value = "System failure"

In the "THEN perform the following actions block:
Click "ADD ACTION".
Action = "Send (<your syslog server>)"

Click "SAVE".

Check Contents

1. Check Server Configuration.

If using Syslog Server:
Verify third-party server is used to receive communication-related notifications.
Check for a configured Syslog Server.
In the UI, navigate to Admin >> Integrations.
Click "LAUNCH" in the Syslog section.

If no server is configured or the status is not "Connected", this is a finding.

If no recipient is configured, this is a finding.

2. Check Rules:
Navigate to Notification >> RULES Tab.
Verify a rule exists and has the following:
Action = "Send (<your syslog server>)"
Criteria = "Notification Type Equals System"
"Notification Type Equals System Failure"

If a rule does not exist with the correct Action and Criteria, this is a finding.

Vulnerability Number

V-271070

Documentable

False

Rule Version

DRAG-OT-002120

Severity Override Guidance

1. Check Server Configuration.

If using Syslog Server:
Verify third-party server is used to receive communication-related notifications.
Check for a configured Syslog Server.
In the UI, navigate to Admin >> Integrations.
Click "LAUNCH" in the Syslog section.

If no server is configured or the status is not "Connected", this is a finding.

If no recipient is configured, this is a finding.

2. Check Rules:
Navigate to Notification >> RULES Tab.
Verify a rule exists and has the following:
Action = "Send (<your syslog server>)"
Criteria = "Notification Type Equals System"
"Notification Type Equals System Failure"

If a rule does not exist with the correct Action and Criteria, this is a finding.

Check Content Reference

M

Target Key

5675