Skip to content

ForeScout CounterACT ALG Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-NET-000334-ALG-000050

    Group
  • CounterACT must off-load audit records onto a centralized log server.

    Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity. Th...
    Rule Medium Severity
  • SRG-NET-000337-ALG-000096

    Group
  • SRG-NET-000339-ALG-000090

    Group
  • CounterACT, when providing user authentication intermediary services, must implement multifactor authentication for remote access to non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.

    For remote access to non-privileged accounts, the purpose of requiring a device that is separate from the information system gaining access for one of the factors during multifactor authentication ...
    Rule Medium Severity
  • SRG-NET-000511-ALG-000051

    Group
  • SRG-NET-000089-ALG-000055

    Group
  • CounterACT must use an Enterprise Manager or other high availability solution to ensure redundancy in case of audit failure in this critical network access control and security service.

    It is critical that when the network element is at risk of failing to process audit logs as required, it take action to mitigate the failure. Audit processing failures include: software/hardware er...
    Rule Medium Severity
  • CounterACT, when providing user access control intermediary services, must display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to the network.

    Display of a standardized and approved use notification before granting access to the network ensures privacy and security notification verbiage used is consistent with DoD requirements. System us...
    Rule Medium Severity
  • If user authentication services are provided, CounterACT must be configured with a pre-established trust relationship and mechanisms with a central directory service that validates user account access authorizations and privileges.

    User account and privilege validation must be centralized in order to prevent unauthorized access using changed or revoked privileges. CounterACT can implement functions such as traffic filtering,...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules