Cisco ISE NDM Security Technical Implementation Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one uppercase character be used.
<VulnDiscussion>Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity,...Rule Medium Severity -
SRG-APP-000167-NDM-000255
<GroupDescription></GroupDescription>Group -
For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one lowercase character be used.
<VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...Rule Medium Severity -
SRG-APP-000168-NDM-000256
<GroupDescription></GroupDescription>Group -
The Cisco ISE must change the password for the local CLI and web-based account when members who have access to the password leave the role and are no longer authorized access.
<VulnDiscussion>If shared/group account credentials are not terminated when individuals leave the group, the user that left the group can sti...Rule Medium Severity -
SRG-APP-000026-NDM-000208
<GroupDescription></GroupDescription>Group -
For the local web-based account of last resort, the Cisco ISE must automatically audit account creation.
<VulnDiscussion>Upon gaining access to a network device, an attacker will often first attempt to create a persistent method of reestablishing...Rule Medium Severity -
SRG-APP-000027-NDM-000209
<GroupDescription></GroupDescription>Group -
For the local web-based account of last resort and the default local CLI account, the Cisco ISE must automatically audit account modification.
<VulnDiscussion>Since the accounts in the network device are privileged or system-level accounts, account management is vital to the security...Rule Medium Severity -
SRG-APP-000028-NDM-000210
<GroupDescription></GroupDescription>Group -
For the local web-based account of last resort, the Cisco ISE must automatically audit account disabling actions.
<VulnDiscussion>Account management, as a whole, ensures access to the network device is being controlled in a secure manner by granting acces...Rule Medium Severity -
SRG-APP-000029-NDM-000211
<GroupDescription></GroupDescription>Group -
For the local account of last resort, the Cisco ISE must automatically audit account removal actions.
<VulnDiscussion>Account management, as a whole, ensures access to the network device is being controlled in a secure manner by granting acces...Rule Medium Severity -
SRG-APP-000319-NDM-000283
<GroupDescription></GroupDescription>Group -
The Cisco ISE must automatically audit account enabling actions.
<VulnDiscussion>Once an attacker establishes initial access to a system, the attacker often attempts to create a persistent method of reestab...Rule Low Severity -
SRG-APP-000148-NDM-000346
<GroupDescription></GroupDescription>Group -
The Cisco ISE must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
<VulnDiscussion>This requirement supports non-repudiation of actions taken by an administrator and is required in order to maintain the integ...Rule Medium Severity -
SRG-APP-000091-NDM-000223
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when successful attempts to access privileges occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000495-NDM-000318
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when successful attempts to modify administrator privileges occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000499-NDM-000319
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when successful attempts to delete administrator privileges occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000503-NDM-000320
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when successful logon attempts occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000504-NDM-000321
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records for privileged activities or other system-level access.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000506-NDM-000323
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when concurrent logons from different workstations occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000357-NDM-000293
<GroupDescription></GroupDescription>Group -
The Cisco ISE must limit audit record storage capacity for all locally stored logs.
<VulnDiscussion>In order to ensure network devices have a sufficient storage capacity in which to write the audit logs, they need to be able ...Rule Medium Severity -
SRG-APP-000515-NDM-000325
<GroupDescription></GroupDescription>Group -
The Cisco ISE must configure a remote syslog where audit records are stored on a centralized logging target that is different from the system being audited.
<VulnDiscussion>Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Storing audit logs to a...Rule Medium Severity -
SRG-APP-000360-NDM-000295
<GroupDescription></GroupDescription>Group -
The Cisco ISE must send an alarm to one or more individuals when the monitoring collector process has an error or failure.
<VulnDiscussion>It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required....Rule Medium Severity -
SRG-APP-000373-NDM-000298
<GroupDescription></GroupDescription>Group -
The Cisco ISE must be running an operating system release that is currently supported by the vendor.
<VulnDiscussion>Network devices running an unsupported operating system lack current security fixes required to mitigate the risks associated...Rule Medium Severity -
SRG-APP-000516-NDM-000334
<GroupDescription></GroupDescription>Group -
For accounts using password authentication, the Cisco ISE must implement replay-resistant authentication mechanisms for network access to privileged accounts.
<VulnDiscussion>A replay attack may enable an unauthorized user to gain access to the application. Authentication sessions between the authen...Rule Medium Severity -
SRG-APP-000395-NDM-000310
<GroupDescription></GroupDescription>Group -
For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one digit be used.
<VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...Rule Medium Severity -
SRG-APP-000169-NDM-000257
<GroupDescription></GroupDescription>Group -
For accounts using password authentication, the Cisco ISE must enforce password complexity by requiring that at least one special character be used.
<VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...Rule Medium Severity -
SRG-APP-000172-NDM-000259
<GroupDescription></GroupDescription>Group -
The Cisco ISE must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).
<VulnDiscussion>Without authenticating devices, unidentified or unknown devices may be introduced, thereby facilitating malicious activity. B...Rule Medium Severity -
SRG-APP-000395-NDM-000347
<GroupDescription></GroupDescription>Group -
The Cisco ISE must authenticate Network Time Protocol (NTP) sources using authentication that is cryptographically based.
<VulnDiscussion>If NTP is not authenticated, an attacker can introduce a rogue NTP server. This rogue server can then be used to send incorre...Rule Medium Severity -
SRG-APP-000164-NDM-000252
<GroupDescription></GroupDescription>Group -
For accounts using password authentication, the Cisco ISE must enforce a minimum 15-character password length.
<VulnDiscussion>Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute...Rule Medium Severity -
SRG-APP-000166-NDM-000254
<GroupDescription></GroupDescription>Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.