STIGQter STIGQter: STIG Summary: ForeScout CounterACT ALG Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 26 Jan 2018:

CounterACT must off-load audit records onto a centralized log server.

DISA Rule

SV-90631r1_rule

Vulnerability Number

V-75943

Group Title

SRG-NET-000334-ALG-000050

Rule Version

CACT-AG-000010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure CounterACT to off-load audit records onto a centralized log server.

1. Connect to CounterACT’s Admin Console and log in.
2. Go to Tools >> Options >> Plugins >> Syslog.
3. Ensure a Syslog server is configured in the "Send To" tab.
4. On the Events Filtering Tab, ensure all radio buttons associated with NAC Events, Threat Protection, System Logs, User Operations, and Operating System messages are selected.
5. Select "OK". (Select "Apply" if changes were made.)

Check Contents

Verify CounterACT off-loads audit records onto a centralized log server.

1. Connect to CounterACT’s Admin Console and log in.
2. Go to Tools >> Options >> Plugins >> Syslog.
3. Verify a Syslog server is configured in the "Send To" tab.
4. On the Events Filtering Tab, ensure all radio buttons associated with NAC Events, Threat Protection, System Logs, User Operations, and Operating System messages are selected.

If CounterACT does not off-load audit records onto a centralized log server, this is a finding.

Vulnerability Number

V-75943

Documentable

False

Rule Version

CACT-AG-000010

Severity Override Guidance

Verify CounterACT off-loads audit records onto a centralized log server.

1. Connect to CounterACT’s Admin Console and log in.
2. Go to Tools >> Options >> Plugins >> Syslog.
3. Verify a Syslog server is configured in the "Send To" tab.
4. On the Events Filtering Tab, ensure all radio buttons associated with NAC Events, Threat Protection, System Logs, User Operations, and Operating System messages are selected.

If CounterACT does not off-load audit records onto a centralized log server, this is a finding.

Check Content Reference

M

Target Key

3223

Comments