Check: FORE-NC-000150
Forescout Network Access Control STIG:
FORE-NC-000150
(in versions v1 r4 through v1 r3)
Title
Forescout must be configured to log records onto a centralized events server. This is required for compliance with C2C Step 1. (Cat II impact)
Discussion
Keeping an established, connection-oriented audit record is essential to keeping audit logs in accordance with DoD requirements.
Check Content
If DoD is not at C2C Step 1 or higher, this is not a finding. 1. Go to Tools >> Options >> Syslog. 2. Verify a central log server's IP address is configured. If Forescout does not configured to log records onto a centralized events server, this is a finding.
Fix Text
Configure Syslog server with TCP, as well as configure Syslog to alert if the communication between the Syslog server and the Forescout appliance loses connectivity. 1. Go to Tools >> Options >> Syslog. 2. Click Add/Edit. 3. Configure the Syslog: - Syslog Server IP address - Server Port - Server Protocol set to TCP - Check the Use TLS setting - Configure the Identity, Facility, and Severity. 4. Click "Ok". 5. Click "Apply". Note: A secondary syslog server is required to fully meet this requirement (covered in NDM STIG). Use the same instructions to configure a second syslog.
Additional Identifiers
Rule ID: SV-233323r856509_rule
Vulnerability ID: V-233323
Group Title: SRG-NET-000333-NAC-001340
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001844 |
The information system provides centralized management and configuration of the content to be captured in audit records generated by organization-defined information system components. |
Controls
Number | Title |
---|---|
AU-3 (2) |
Centralized Management Of Planned Audit Record Content |