Cisco ISE NDM Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
The Cisco ISE must generate audit records when successful attempts to modify administrator privileges occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000499-NDM-000319
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when successful attempts to delete administrator privileges occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000503-NDM-000320
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when successful logon attempts occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000504-NDM-000321
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records for privileged activities or other system-level access.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000506-NDM-000323
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when concurrent logons from different workstations occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000357-NDM-000293
<GroupDescription></GroupDescription>Group -
The Cisco ISE must limit audit record storage capacity for all locally stored logs.
<VulnDiscussion>In order to ensure network devices have a sufficient storage capacity in which to write the audit logs, they need to be able ...Rule Medium Severity -
SRG-APP-000515-NDM-000325
<GroupDescription></GroupDescription>Group -
The Cisco ISE must configure a remote syslog where audit records are stored on a centralized logging target that is different from the system being audited.
<VulnDiscussion>Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Storing audit logs to a...Rule Medium Severity -
SRG-APP-000360-NDM-000295
<GroupDescription></GroupDescription>Group -
The Cisco ISE must send an alarm to one or more individuals when the monitoring collector process has an error or failure.
<VulnDiscussion>It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required....Rule Medium Severity -
SRG-APP-000373-NDM-000298
<GroupDescription></GroupDescription>Group -
The Cisco ISE must be running an operating system release that is currently supported by the vendor.
<VulnDiscussion>Network devices running an unsupported operating system lack current security fixes required to mitigate the risks associated...Rule Medium Severity -
SRG-APP-000516-NDM-000334
<GroupDescription></GroupDescription>Group -
For accounts using password authentication, the Cisco ISE must implement replay-resistant authentication mechanisms for network access to privileged accounts.
<VulnDiscussion>A replay attack may enable an unauthorized user to gain access to the application. Authentication sessions between the authen...Rule Medium Severity -
SRG-APP-000395-NDM-000310
<GroupDescription></GroupDescription>Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.