Check: FORE-NM-000170
Forescout Network Device Management STIG:
FORE-NM-000170
(in version v1 r1)
Title
Forescout must be configured to use Coordinated Universal Time (UTC). (Cat II impact)
Discussion
If time stamps are not consistently applied and there is no common time reference, it is difficult to perform forensic analysis. Time stamps generated by the application include date and time. Time is commonly expressed in Coordinated Universal Time (UTC), a modern continuation of Greenwich Mean Time (GMT), or local time with an offset from UTC.
Check Content
Determine if Forescout records time stamps for log records that can be mapped to UTC. This requirement may be verified by demonstration or configuration review. Verify by connecting to the appliance via SSH using standard user/operator privilege. 1. Type "date" at the command prompt. 2. Verify the date references accurate time and "UTC" shows just before the year. If Forescout does not record time stamps for log records that can be mapped to UTC, this is a finding.
Fix Text
Configure Forescout to record time stamps for log records that can be mapped to UTC. Note: Updating time preferences will force Forescout into maintenance mode and the service must be restarted. Use a scheduled outage for planned maintenance and stop Forescout service prior to adjusting time settings. 1. Type the following command at the prompt using the IP address of the required NTP server: fstool ntp <ip address> 2. Ensure the date references accurate time and the time zone points to UTC next to the year.
Additional Identifiers
Rule ID: SV-230945r615886_rule
Vulnerability ID: V-230945
Group Title: SRG-APP-000374-NDM-000299
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001890 |
The information system records time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT). |
Controls
Number | Title |
---|---|
AU-8 |
Time Stamps |