STIGUI
V-285649CAT II — Medium severitySV-285649r1273142_rule

The Content Analysis System (CAS) must be configured to generate audit records and alert administrators upon detecting potential system or file integrity violations using Intelligent Connection Traffic Monitoring (ICTM) and Hash Reputation.

Rule version BCAS-ND-001855 · STIG v1 · 2026-09-16

Discussion

Without an audit capability, an integrity violation may not be detected. Organizations select response actions based on types of software, specific software, or information for which there are potential integrity violations. The integrity verification application must be configured to perform one or more of following actions: Generates an audit record; alerts current user; alerts organization-defined personnel or roles. The organization may define additional actions to be taken.

Check

Verify ICTM is enabled to generate alerts and Hash Reputation engines are enabled to generate audit records for integrity violations with the following steps:

1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> ICTM. 3. Verify "Enable Intelligent Connection Traffic Monitoring (ICTM)" is checked and configured to send an alert. 4. Navigate to System >> Licensing. 5. Under "Hash Reputation", verify "File Reputation" and "Custom Whitelist/Blacklist" are checked.

If ICTM alerting is disabled, or if the required hash reputation engines are unselected, this is a finding.

Fix

Configure ICTM alerting and enable Hash Reputation mechanisms to respond to integrity violations with the following steps:

1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> ICTM. 3. Check the box for "Enable Intelligent Connection Traffic Monitoring (ICTM)". 4. Check the box to "Send an alert when warning level is reached", set the level to "20" seconds, and click "Save Changes". 5. Navigate to System >> Licensing. 6. Under "Hash Reputation", check the boxes for "File Reputation" and "Custom Whitelist/Blacklist". 7. Click "Save Changes".

Identifiers

Group ID
V-285649
Group title
SRG-APP-000516-NDM-000317
Rule ID
SV-285649r1273142_rule
Check ID
C-90329r1273064_chk
Fix ID
F-90234r1273065_fix