Skip to content

Cisco IOS XE Router NDM Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000373-NDM-000298

    Group
  • SRG-APP-000395-NDM-000310

    Group
  • The Cisco router must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).

    Without authenticating devices, unidentified or unknown devices may be introduced, thereby facilitating malicious activity. Bidirectional authentication provides stronger safeguards to validate the...
    Rule Medium Severity
  • SRG-APP-000395-NDM-000310

    Group
  • SRG-APP-000395-NDM-000347

    Group
  • SRG-APP-000411-NDM-000330

    Group
  • SRG-APP-000412-NDM-000331

    Group
  • SRG-APP-000499-NDM-000319

    Group
  • SRG-APP-000503-NDM-000320

    Group
  • The Cisco router must be configured to generate audit records when successful/unsuccessful logon attempts occur.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000504-NDM-000321

    Group
  • SRG-APP-000516-NDM-000336

    Group
  • SRG-APP-000516-NDM-000340

    Group
  • SRG-APP-000516-NDM-000344

    Group
  • The Cisco router must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.

    For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure...
    Rule Medium Severity
  • SRG-APP-000516-NDM-000350

    Group
  • SRG-APP-000516-NDM-000351

    Group
  • The Cisco router must be running an IOS release that is currently supported by Cisco Systems.

    Network devices running an unsupported operating system lack current security fixes required to mitigate the risks associated with recent vulnerabilities. Running a supported release also enables o...
    Rule High Severity
  • The Cisco router must be configured to limit the number of concurrent management sessions to an organization-defined number.

    Device management includes the ability to control the number of administrators and management sessions that manage a device. Limiting the number of allowed administrators and sessions per administr...
    Rule Medium Severity
  • The Cisco router must be configured to automatically audit account modification.

    Since the accounts in the network device are privileged or system-level accounts, account management is vital to the security of the network device. Account management by a designated authority ens...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules