4.4.3 Ensure all Application Control related traffic is logged

Information

Ensure no category is set to "Allow" on FortiGate Application Control.

Any category that is set as "Allow" on Application Control will not be logged. This creates a visibility gap on security investigation. This includes "Unknown Applications" category.

Solution

On GUI:

1. Go to "Security Profiles" > "Application Control".
2. Select the relevant App Control profile.
3. Change any categories with "Allow" action to "Monitor".

Impact:

Visibility gap, which affects incident forensics and response.

See Also

https://workbench.cisecurity.org/benchmarks/15284

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, 800-53|SI-4(4)

Plugin: FortiGate

Control ID: ddc05f86c55ade6354cf6811940108f449a97ec5e232ce5ac7e56ee19a536dbf