STIGQter STIGQter: STIG Summary: ForeScout CounterACT NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 12 Sep 2017:

CounterACT must be configured to synchronize internal information system clocks with the organizations primary and secondary NTP servers.

DISA Rule

SV-90929r1_rule

Vulnerability Number

V-76241

Group Title

SRG-APP-000373-NDM-000298

Rule Version

CACT-NM-000038

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure CounterACT to synchronize internal information system clocks with the primary and secondary time sources located in different geographic regions using redundant authoritative time sources.

1. Open an SSH session and authenticate to the CounterACT command line.
2. Configure the primary and secondary NTP servers with the command "fstool ntp setup <ip address>".

Check Contents

Determine if CounterACT is configured to synchronize internal clocks with the organization's primary and secondary NTP servers.

1. Open an SSH session and authenticate to the CounterACT command line.
2. Verify a primary and secondary NTP server has been configured with the command "fstool ntp".

If CounterACT is not configured to synchronize internal information system clocks with the organization's primary and secondary NTP servers, this is a finding.

Vulnerability Number

V-76241

Documentable

False

Rule Version

CACT-NM-000038

Severity Override Guidance

Determine if CounterACT is configured to synchronize internal clocks with the organization's primary and secondary NTP servers.

1. Open an SSH session and authenticate to the CounterACT command line.
2. Verify a primary and secondary NTP server has been configured with the command "fstool ntp".

If CounterACT is not configured to synchronize internal information system clocks with the organization's primary and secondary NTP servers, this is a finding.

Check Content Reference

M

Target Key

3225

Comments