A10 Networks ADC NDM Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000068-NDM-000215
Group -
The A10 Networks ADC must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.
Display of the DoD-approved use notification before granting access to the network device ensures privacy and security notification verbiage used is consistent with applicable federal laws, Executi...Rule Low Severity -
SRG-APP-000090-NDM-000222
Group -
The A10 Networks ADC must prohibit the use of unencrypted protocols for network access to privileged accounts.
Passwords need to be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily c...Rule Medium Severity -
SRG-APP-000065-NDM-000214
Group -
SRG-APP-000098-NDM-000228
Group -
The A10 Networks ADC must produce audit log records containing information (FQDN, unique hostname, management or loopback IP address) to establish the source of events.
In order to compile an accurate risk assessment and provide forensic analysis, it is essential for security personnel to know the source of the event. The source may be a component, module, or proc...Rule Low Severity -
SRG-APP-000101-NDM-000231
Group -
The A10 Networks ADC must have command auditing enabled.
Reconstruction of harmful events or forensic analysis is not possible if audit records do not contain enough information. The organization must maintain audit trails in sufficient detail to reconst...Rule Low Severity -
SRG-APP-000108-NDM-000232
Group -
SRG-APP-000125-NDM-000241
Group -
The A10 Networks ADC must back up audit records at least every seven days onto a different system or system component than the system or component being audited.
Protection of log data includes assuring log data is not accidentally lost or deleted. Regularly backing up audit records to a different system or onto separate media than the system being audited ...Rule Low Severity -
SRG-APP-000142-NDM-000245
Group -
SRG-APP-000190-NDM-000267
Group -
SRG-APP-000148-NDM-000246
Group -
The A10 Networks ADC must not have any shared accounts (other than the emergency administration account).
To assure accountability and prevent unauthenticated access, organizational administrators must be uniquely identified and authenticated for all network management accesses to prevent potential mis...Rule Medium Severity -
SRG-APP-000148-NDM-000246
Group -
The A10 Networks ADC must not use the default admin account.
To assure accountability and prevent unauthenticated access, organizational administrators must be uniquely identified and authenticated for all network management accesses to prevent potential mis...Rule High Severity -
SRG-APP-000156-NDM-000250
Group -
The A10 Networks ADC must implement replay-resistant authentication mechanisms for network access to privileged accounts.
A replay attack may enable an unauthorized user to gain access to the application. Authentication sessions between the authenticator and the application validating the user credentials must not be ...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.