Skip to content

Forescout must be configured to notify the user before proceeding with remediation of the user's endpoint device when automated remediation is used. This is required for compliance with C2C Step 3.

An XCCDF Rule

Description

<VulnDiscussion>Connections that bypass established security controls should be allowed only in cases of administrative need. These procedures and use cases must be approved by the Information System Security Manager (ISSM). This setting may be sent from the assessment server, a central server, or from the remediation server. Verify the user is notified and accepts (e.g., using an accept button) that remediation is needed and is about to begin.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-233313r811375_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Log on to the Forescout UI.

1. Select the "Policy" tab. 
2. Select a compliance policy, then click "Edit".
3. In the Sub-Rules section, select a policy and click "Edit". 
4. From the Actions section, click Add >> Notify >> and select a notification method.