4.1.1 Detect Botnet Connections

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Interfaces which are classified as 'WAN' and are used by a policy should use an IPS sensor which block or monitor outgoing connections to botnet sites.

Rationale:

Blocking outgoing connections to known Botnets should be utilized in a Defense In Depth network design

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Apply an IPS Sensor with 'Scan Outgoing Connections to Botnet Sites' set to 'Block' on all firewall policies with traffic exiting the network to a 'WAN' interface.

See Also

https://workbench.cisecurity.org/files/4077

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6

Plugin: FortiGate

Control ID: b2f4a44abfba43bf9ba154cd800085a0f30a1954dec9d21409522c405bb27d79