STIGQter STIGQter: STIG Summary: Forescout Network Device Management Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 20 Nov 2020:

Forescout must prevent the installation of patches, service packs, plug-ins, or modules without verification the update has been digitally signed using a certificate that is recognized and approved by the organization.

DISA Rule

SV-230949r615886_rule

Vulnerability Number

V-230949

Group Title

SRG-APP-000131-NDM-000243

Rule Version

FORE-NM-000220

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

When Forescout updates are downloaded, whether from the DoD update server or the updates.forescout.com portal, each update consists of an MD5 hash. Manually inspect, compare, and verify the MD5 hash against the Forescout website to ensure that the software has come from the Forescout server.

Check Contents

Verify by inspecting the SSP or documentation to determine if there is a procedure for validating the MD5 hash against the Forescout updates.forescout.com portal to ensure that the software has come from the Forescout server.

If the site does not have a documented process to prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate recognized and approved by the organization, this is a finding.

Vulnerability Number

V-230949

Documentable

False

Rule Version

FORE-NM-000220

Severity Override Guidance

Verify by inspecting the SSP or documentation to determine if there is a procedure for validating the MD5 hash against the Forescout updates.forescout.com portal to ensure that the software has come from the Forescout server.

If the site does not have a documented process to prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate recognized and approved by the organization, this is a finding.

Check Content Reference

M

Target Key

5245

Comments