SV-230930r615886_rule
V-230930
SRG-APP-000001-NDM-000200
FORE-NM-000010
CAT III
10
Configure Forescout to require a limit of one session per user.
1. Log on to the Forescout Administrator UI.
2. From the menu, select Tools >> Options >> CounterAct user profiles >> Password and Sessions >> Session.
3. Check "allow only one login session per user".
4. Select the "Terminate existing session upon new login" radio button.
5. Select "Console and web portal sessions cannot exist concurrently".
Determine if Forescout requires a limit of one session per user. This requirement may be verified by demonstration or configuration review.
1. Log on to the Forescout Administrator UI.
2. From the menu, select Tools >> Options >> CounterAct user profiles >> Password and Sessions >> Session.
3. Verify the "allow only one login session per user", "Terminate existing session upon new login", and "Console and web portal sessions cannot exist concurrently".
If Forescout does not enforce one session per user, this is a finding.
V-230930
False
FORE-NM-000010
Determine if Forescout requires a limit of one session per user. This requirement may be verified by demonstration or configuration review.
1. Log on to the Forescout Administrator UI.
2. From the menu, select Tools >> Options >> CounterAct user profiles >> Password and Sessions >> Session.
3. Verify the "allow only one login session per user", "Terminate existing session upon new login", and "Console and web portal sessions cannot exist concurrently".
If Forescout does not enforce one session per user, this is a finding.
M
5245