Cisco IOS XE Router NDM Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000373-NDM-000298
Group -
SRG-APP-000395-NDM-000310
Group -
The Cisco router must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).
Without authenticating devices, unidentified or unknown devices may be introduced, thereby facilitating malicious activity. Bidirectional authentication provides stronger safeguards to validate the...Rule Medium Severity -
SRG-APP-000395-NDM-000310
Group -
SRG-APP-000395-NDM-000347
Group -
SRG-APP-000411-NDM-000330
Group -
SRG-APP-000412-NDM-000331
Group -
SRG-APP-000499-NDM-000319
Group -
SRG-APP-000503-NDM-000320
Group -
The Cisco router must be configured to generate audit records when successful/unsuccessful logon attempts occur.
Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...Rule Medium Severity -
SRG-APP-000504-NDM-000321
Group -
SRG-APP-000516-NDM-000336
Group -
SRG-APP-000516-NDM-000340
Group -
SRG-APP-000516-NDM-000344
Group -
The Cisco router must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.
For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure...Rule Medium Severity -
SRG-APP-000516-NDM-000350
Group -
SRG-APP-000516-NDM-000351
Group -
The Cisco router must be running an IOS release that is currently supported by Cisco Systems.
Network devices running an unsupported operating system lack current security fixes required to mitigate the risks associated with recent vulnerabilities. Running a supported release also enables o...Rule High Severity -
The Cisco router must be configured to limit the number of concurrent management sessions to an organization-defined number.
Device management includes the ability to control the number of administrators and management sessions that manage a device. Limiting the number of allowed administrators and sessions per administr...Rule Medium Severity -
The Cisco router must be configured to automatically audit account modification.
Since the accounts in the network device are privileged or system-level accounts, account management is vital to the security of the network device. Account management by a designated authority ens...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.