CIS Cisco IOS XE 16.x v2.1.0 L1

Audit Details

Name: CIS Cisco IOS XE 16.x v2.1.0 L1

Updated: 6/24/2024

Authority: CIS

Plugin: Cisco

Revision: 1.0

Estimated Item Count: 57

File Details

Filename: CIS_Cisco_IOS_XE_16.x_v2.1.0_L1.audit

Size: 139 kB

MD5: e7c54d323808bba2a2cff7f563dd999c
SHA256: 69a64933303198f900fe2b5224ec09f24cc3471f022539904ccdccc1b09dc7ac

Audit Items

DescriptionCategories
1.1.1 Enable 'aaa new-model'

ACCESS CONTROL

1.1.2 Enable 'aaa authentication login'

ACCESS CONTROL

1.1.3 Enable 'aaa authentication enable default'

ACCESS CONTROL

1.1.4 Set 'login authentication for 'line vty'

ACCESS CONTROL

1.1.5 Set 'login authentication for 'ip http'

ACCESS CONTROL

1.2.1 Set 'privilege 1' for local users

IDENTIFICATION AND AUTHENTICATION

1.2.2 Set 'transport input ssh' for 'line vty' connections

IDENTIFICATION AND AUTHENTICATION

1.2.3 Set 'no exec' for 'line aux 0'

SYSTEM AND INFORMATION INTEGRITY

1.2.4 Create 'access-list' for use with 'line vty'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.2.5 Set 'access-class' for 'line vty'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.2.6 Set 'exec-timeout' to less than or equal to 10 minutes for 'line aux 0'

ACCESS CONTROL

1.2.7 Set 'exec-timeout' to less than or equal to 10 minutes 'line console 0'

ACCESS CONTROL

1.2.8 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty'

ACCESS CONTROL

1.2.9 Set 'transport input none' for 'line aux 0'

ACCESS CONTROL

1.2.10 Set 'http Secure-server' limit

ACCESS CONTROL

1.2.11 Set 'exec-timeout' to less than or equal to 10 min on 'ip http'

ACCESS CONTROL

1.3.1 Set the 'banner-text' for 'banner exec'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.2 Set the 'banner-text' for 'banner login'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.3 Set the 'banner-text' for 'banner motd'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.4 Set the 'banner-text' for 'webauth banner'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.4.1 Set 'password' for 'enable secret'

ACCESS CONTROL

1.4.2 Enable 'service password-encryption'

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.4.3 Set 'username secret' for all local users

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.5.1 Set 'no snmp-server' to disable SNMP when unused

SYSTEM AND INFORMATION INTEGRITY

1.5.2 Unset 'private' for 'snmp-server community'

SYSTEM AND INFORMATION INTEGRITY

1.5.3 Unset 'public' for 'snmp-server community'

SYSTEM AND INFORMATION INTEGRITY

1.5.4 Do not set 'RW' for any 'snmp-server community'

SYSTEM AND INFORMATION INTEGRITY

1.5.5 Set the ACL for each 'snmp-server community'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.5.6 Create an 'access-list' for use with SNMP

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.5.7 Set 'snmp-server host' when using SNMP

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.5.8 Set 'snmp-server enable traps snmp'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

2.1.1.1.1 Set the 'hostname'

CONFIGURATION MANAGEMENT

2.1.1.1.2 Set the 'ip domain-name'

CONFIGURATION MANAGEMENT

2.1.1.1.3 Set 'modulus' to greater than or equal to 2048 for 'crypto key generate rsa'

SYSTEM AND SERVICES ACQUISITION

2.1.1.1.4 Set 'seconds' for 'ip ssh timeout' for 60 seconds or less

ACCESS CONTROL

2.1.1.1.5 Set maximum value for 'ip ssh authentication-retries'

IDENTIFICATION AND AUTHENTICATION

2.1.1.2 Set version 2 for 'ip ssh version'

CONFIGURATION MANAGEMENT

2.1.2 Set 'no cdp run'

SYSTEM AND INFORMATION INTEGRITY

2.1.3 Set 'no ip bootp server'

SYSTEM AND INFORMATION INTEGRITY

2.1.4 Set 'no service dhcp'

SYSTEM AND INFORMATION INTEGRITY

2.1.5 Set 'no ip identd'

SYSTEM AND INFORMATION INTEGRITY

2.1.6 Set 'service tcp-keepalives-in'

SYSTEM AND INFORMATION INTEGRITY

2.1.7 Set 'service tcp-keepalives-out'

SYSTEM AND INFORMATION INTEGRITY

2.1.8 Set 'no service pad'

SYSTEM AND INFORMATION INTEGRITY

2.2.1 Set 'logging enable'

AUDIT AND ACCOUNTABILITY

2.2.2 Set 'buffer size' for 'logging buffered'

AUDIT AND ACCOUNTABILITY

2.2.3 Set 'logging console critical'

AUDIT AND ACCOUNTABILITY

2.2.4 Set IP address for 'logging host'

AUDIT AND ACCOUNTABILITY, INCIDENT RESPONSE, SYSTEM AND INFORMATION INTEGRITY

2.2.5 Set 'logging trap informational'

AUDIT AND ACCOUNTABILITY

2.2.6 Set 'service timestamps debug datetime'

AUDIT AND ACCOUNTABILITY