SV-230954r616548_rule
V-230954
SRG-APP-000329-NDM-000287
FORE-NM-000270
CAT II
10
Login to Forescout UI.
1. Select Tools >> Options >> CounterACT User Profiles.
2. Select username >> Edit >> Permissions.
Check the SSP against created users and ensure least privilege has been configured properly. Options include Custom accounts for Console Access and Web Access. Each access account is then further established with permissions based on the user's authorizations.
Check the administrative accounts assigned to each role are documented within the SSP and have been configured correctly with least privilege.
1. Log on to Forescout UI.
2. Select Tools >> Options >> CounterACT User Profiles.
3. Select username >> Edit >> Permissions.
Check the SSP against created users and ensure least privilege has been configured properly. Options include Custom accounts for Console Access and Web Access. Each access account is then further established with permissions based on the user's authorizations.
If Forescout does not enforce organization-defined, role-based access control policies over defined subjects and objects, this is a finding.
V-230954
False
FORE-NM-000270
Check the administrative accounts assigned to each role are documented within the SSP and have been configured correctly with least privilege.
1. Log on to Forescout UI.
2. Select Tools >> Options >> CounterACT User Profiles.
3. Select username >> Edit >> Permissions.
Check the SSP against created users and ensure least privilege has been configured properly. Options include Custom accounts for Console Access and Web Access. Each access account is then further established with permissions based on the user's authorizations.
If Forescout does not enforce organization-defined, role-based access control policies over defined subjects and objects, this is a finding.
M
5245