II - Mission Support Public
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000068-NDM-000215
<GroupDescription></GroupDescription>Group -
For the local account of last resort, the Cisco ISE must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.
<VulnDiscussion>Display of the DoD-approved use notification before granting access to the network device ensures privacy and security notifi...Rule Medium Severity -
SRG-APP-000080-NDM-000220
<GroupDescription></GroupDescription>Group -
The Cisco ISE must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
<VulnDiscussion>This requirement supports non-repudiation of actions taken by an administrator and is required in order to maintain the integ...Rule Medium Severity -
SRG-APP-000091-NDM-000223
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when successful attempts to access privileges occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000495-NDM-000318
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when successful attempts to modify administrator privileges occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000499-NDM-000319
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when successful attempts to delete administrator privileges occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000503-NDM-000320
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when successful logon attempts occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000504-NDM-000321
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records for privileged activities or other system-level access.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000506-NDM-000323
<GroupDescription></GroupDescription>Group -
The Cisco ISE must generate audit records when concurrent logons from different workstations occur.
<VulnDiscussion>Without generating audit records that are specific to the security and mission needs of the organization, it would be difficu...Rule Medium Severity -
SRG-APP-000357-NDM-000293
<GroupDescription></GroupDescription>Group -
The Cisco ISE must limit audit record storage capacity for all locally stored logs.
<VulnDiscussion>In order to ensure network devices have a sufficient storage capacity in which to write the audit logs, they need to be able ...Rule Medium Severity -
SRG-APP-000515-NDM-000325
<GroupDescription></GroupDescription>Group -
The Cisco ISE must configure a remote syslog where audit records are stored on a centralized logging target that is different from the system being audited.
<VulnDiscussion>Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Storing audit logs to a...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.