STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Forescout Network Access Control Security Technical Implementation Guide

V-233313

CAT II (Medium)

Forescout must be configured to notify the user before proceeding with remediation of the user's endpoint device when automated remediation is used. This is required for compliance with C2C Step 3.

Rule ID

SV-233313r1113802_rule

STIG

Forescout Network Access Control Security Technical Implementation Guide

Version

V2R4

CCIs

CCI-000213

Discussion

Connections that bypass established security controls should be allowed only in cases of administrative need. These procedures and use cases must be approved by the information system security manager (ISSM). Unless an exception is approved to not require notification of the user, the following configurations must be implemented: - This setting may be sent from the assessment server, a central server, or from the remediation server. - Verify the user is notified and accepts (e.g., using an accept button) that remediation is needed and is about to begin.

Check Content

If DOD is not at C2C Step 3 or higher, this is not a finding.

Check Forescout policy to ensure that exempt devices that are in need of remediation prompt the user to accept the remediation process, prior to conducting.

1. Log on to the Forescout UI.
2. Select the "Policy" tab. 
3. Review the compliance policy identified by the site representation as the remediation policy, then click "Edit".
4. In the Sub-Rules section, select a policy and click "Edit". 
5. From the Actions section, verify that the policy is configured to notify the user, prior to remediation, that user interaction is required. 

If Forescout is not configured to notify the user before proceeding with remediation of the user's endpoint device when automated remediation is used, this is a finding.

Fix Text

Log on to the Forescout UI.

1. Select the "Policy" tab. 
2. Select a compliance policy, then click "Edit".
3. In the Sub-Rules section, select a policy and click "Edit". 
4. From the Actions section, click Add >> Notify >> and select a notification method.