SV-230972r615886_rule
V-230972
SRG-APP-000516-NDM-000350
FORE-NM-000460
CAT I
10
Establish and document a procedure that periodically checks to ensure audit logs are in keeping with the security best practices of detailed security audit logs.
1. Log on to the Forescout UI.
2. Select Tools >> Options >> Modules >> Syslog >> Add.
3. Configure the:
Server Address
Server Port
Select Use TLS
4. Configure Identify, Facility, and Severity and then select OK >> Apply.
Check the Forescout logs periodically to ensure proper auditing functions are still enabled and have not been changed. A proper security policy performs periodic checks to help ensure the proper information is being gathered in the event of a security breach, or internal/external threat.
If the Forescout auditing functions are disabled or have been changed, this is a finding.
V-230972
False
FORE-NM-000460
Check the Forescout logs periodically to ensure proper auditing functions are still enabled and have not been changed. A proper security policy performs periodic checks to help ensure the proper information is being gathered in the event of a security breach, or internal/external threat.
If the Forescout auditing functions are disabled or have been changed, this is a finding.
M
5245