Certification Compliance

 

Certification Compliance mode is a hardened configuration mode that enables advanced security features. This mode is intended for organizations that need to comply with strict security requirements. You can configure the to run in Certification Compliance mode during the initial Enterprise Manager/Appliance CLI configuration of a clean installation.

Configuration of this mode is irreversible. Verify that your organization needs Forescout to run in this mode before configuring. Changing configuration requires a clean installation of the Appliance.

If your organization does not need to comply with a specific set of strict security requirements, but would still like to follow Forescout security best practices, refer to   in the Administration Guide. Following these best practices allows you to harden your security stature in a more customizable manner, by manually configuring specific options in your environment.

See Configure an Appliance and Configure the Enterprise Manager for details on how to configure Certification Compliance mode.

When the is running in Certification Compliance mode, the following features are affected:

  • FS-CLI. Users are not able to access the Bash shell. FS-CLI, a proprietary Forescout command line interface, is the only CLI shell available.
  • TLS. The TLS version is set to v1.2 with no option to change to lower versions.
  • SNMP. SNMPv3 is set as the default. If you select a different version, a warning appears.
  • NTP. Authenticated NTP is set as the default. If you use unsecure, unauthenticated NTP, a warning appears.
  • Log and database partitions. These partitions are encrypted.
  • FIPS Compliance is enabled.
  • Legacy web portals. The Assets Portal and the Reports Portal are disabled.
  • Additional user actions are written to the Audit Trails.