Rule version BCAS-ND-001855 · STIG v1 · 2026-09-16
Without an audit capability, an integrity violation may not be detected. Organizations select response actions based on types of software, specific software, or information for which there are potential integrity violations. The integrity verification application must be configured to perform one or more of following actions: Generates an audit record; alerts current user; alerts organization-defined personnel or roles. The organization may define additional actions to be taken.
Verify ICTM is enabled to generate alerts and Hash Reputation engines are enabled to generate audit records for integrity violations with the following steps:
1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> ICTM. 3. Verify "Enable Intelligent Connection Traffic Monitoring (ICTM)" is checked and configured to send an alert. 4. Navigate to System >> Licensing. 5. Under "Hash Reputation", verify "File Reputation" and "Custom Whitelist/Blacklist" are checked.
If ICTM alerting is disabled, or if the required hash reputation engines are unselected, this is a finding.
Configure ICTM alerting and enable Hash Reputation mechanisms to respond to integrity violations with the following steps:
1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> ICTM. 3. Check the box for "Enable Intelligent Connection Traffic Monitoring (ICTM)". 4. Check the box to "Send an alert when warning level is reached", set the level to "20" seconds, and click "Save Changes". 5. Navigate to System >> Licensing. 6. Under "Hash Reputation", check the boxes for "File Reputation" and "Custom Whitelist/Blacklist". 7. Click "Save Changes".