Skip to content

The Cisco ISE must prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.

An XCCDF Rule

Description

<VulnDiscussion>Preventing non-privileged users from executing privileged functions mitigates the risk that unauthorized individuals or processes may gain unnecessary access to information or privileges. Privileged functions include, for example, establishing accounts, performing system integrity checks, or administering cryptographic key management activities. Non-privileged users are individuals that do not possess appropriate authorizations.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-242615r879717_rule
Severity
High
References
Updated



Remediation - Manual Procedure

Configure Role Based Access Control to ensure only administrator accounts have admin or super admin rights. 

From web Admin portal: 
1. Navigate to Administration >> System >> Admin Access >> Authorization >> Permissions > Policy.
2. Take note of admin account groups.
3. Navigate to Administration >> System >> Admin Access >> Administrators >> Admin Users.