STIGQter STIGQter: STIG Summary: ForeScout CounterACT ALG Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 26 Jan 2018:

CounterACT must off-load audit records onto a centralized log server in real time.

DISA Rule

SV-90877r1_rule

Vulnerability Number

V-76189

Group Title

SRG-NET-000511-ALG-000051

Rule Version

CACT-AG-000014

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure CounterACT to off-load onto a centralized log server in real time.

1. Connect to CounterACT’s Admin Console and log in.
2. Go to Tools >> Options >> Plugins >> Syslog.
3. Ensure a Syslog server is configured in the "Send To" tab.
4. On the Events Filtering Tab, ensure all radio buttons associated with NAC Events, Threat Protection, System Logs, User Operations, and Operating systems messages are selected.

Check Contents

Verify CounterACT off-loads audit records onto a centralized log server in real time.

1. Connect to CounterACT’s Admin Console and log in.
2. Go to Tools >> Options >> Plugins >> Syslog.
3. Verify a Syslog server is configured in the "Send To" tab.
4. On the Events Filtering Tab, Verify all radio buttons associated with NAC Events, Threat Protection, System Logs, User Operations, and Operating systems messages are selected.

If CounterACT does not off-load onto a centralized log server in real time, this is a finding.

Vulnerability Number

V-76189

Documentable

False

Rule Version

CACT-AG-000014

Severity Override Guidance

Verify CounterACT off-loads audit records onto a centralized log server in real time.

1. Connect to CounterACT’s Admin Console and log in.
2. Go to Tools >> Options >> Plugins >> Syslog.
3. Verify a Syslog server is configured in the "Send To" tab.
4. On the Events Filtering Tab, Verify all radio buttons associated with NAC Events, Threat Protection, System Logs, User Operations, and Operating systems messages are selected.

If CounterACT does not off-load onto a centralized log server in real time, this is a finding.

Check Content Reference

M

Target Key

3223

Comments