Cisco ASA NDM Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000395-NDM-000310
Group -
SRG-APP-000026-NDM-000208
Group -
SRG-APP-000027-NDM-000209
Group -
The Cisco ASA must be configured to automatically audit account modification.
Since the accounts in the network device are privileged or system-level accounts, account management is vital to the security of the network device. Account management by a designated authority ens...Rule Medium Severity -
SRG-APP-000028-NDM-000210
Group -
The Cisco ASA must be configured to automatically audit account-disabling actions.
Account management, as a whole, ensures access to the network device is being controlled in a secure manner by granting access to only authorized personnel. Auditing account disabling actions will ...Rule Medium Severity -
SRG-APP-000029-NDM-000211
Group -
The Cisco ASA must be configured to automatically audit account removal actions.
Account management, as a whole, ensures access to the network device is being controlled in a secure manner by granting access to only authorized personnel. Auditing account removal actions will su...Rule Medium Severity -
SRG-APP-000038-NDM-000213
Group -
SRG-APP-000068-NDM-000215
Group -
SRG-APP-000080-NDM-000220
Group -
SRG-APP-000091-NDM-000223
Group -
The Cisco ASA must be configured to generate audit records when successful/unsuccessful attempts to access privileges occur.
Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...Rule Medium Severity -
SRG-APP-000095-NDM-000225
Group -
SRG-APP-000096-NDM-000226
Group -
The Cisco ASA must be configured to produce audit records containing information to establish when (date and time) the events occurred.
It is essential for security personnel to know what is being done, what was attempted, where it was done, when it was done, and by whom it was done in order to compile an accurate risk assessment. ...Rule Medium Severity -
SRG-APP-000097-NDM-000227
Group -
SRG-APP-000098-NDM-000228
Group -
The Cisco ASA must be configured to produce audit log records containing information to establish the source of events.
In order to compile an accurate risk assessment and provide forensic analysis, it is essential for security personnel to know the source of the event. The source may be a component, module, or proc...Rule Medium Severity -
SRG-APP-000099-NDM-000229
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.