TNS Brocade FabricOS Best Practices

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: TNS Brocade FabricOS Best Practices

Updated: 12/17/2021

Authority: TNS

Plugin: Brocade

Revision: 1.24

Estimated Item Count: 61

File Details

Filename: TNS_Brocade_FabricOS_Best_Practices.audit

Size: 66.3 kB

MD5: f625434c5f95f2797badeb249f10f446
SHA256: 147190f24e14539bc9890a6ce6f1c16a89292ee66a1afa75cbb58713544dc80e

Audit Items

DescriptionCategories
Brocade : 'administrator account is enabled with admin role assigned'

ACCESS CONTROL

Brocade : 'All audit severity level must be audited'

AUDIT AND ACCOUNTABILITY

Brocade : 'Authentication policy must be rejected'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Bottleneck alerts must be enabled'

AUDIT AND ACCOUNTABILITY

Brocade : 'Bottleneck detection must be enabled'

CONFIGURATION MANAGEMENT

Brocade : 'Brocade licenses must not be expired'

CONFIGURATION MANAGEMENT

Brocade : 'Configures filters for a specified audit class'

AUDIT AND ACCOUNTABILITY

Brocade : 'Device Connection Control policy must be rejected'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Disable HTTP IPv4'

CONFIGURATION MANAGEMENT

Brocade : 'Disable HTTP IPv6'

CONFIGURATION MANAGEMENT

Brocade : 'Disable HTTP'

CONFIGURATION MANAGEMENT

Brocade : 'Disable Telnet IPv4'

CONFIGURATION MANAGEMENT

Brocade : 'Disable Telnet IPv6'

CONFIGURATION MANAGEMENT

Brocade : 'Disable TFTP IPv4'

CONFIGURATION MANAGEMENT

Brocade : 'Disable TFTP IPv6'

CONFIGURATION MANAGEMENT

Brocade : 'enable administrator account lockout'

ACCESS CONTROL

Brocade : 'Enable auditcfg'

AUDIT AND ACCOUNTABILITY

Brocade : 'Enable HTTPS IPv4'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Enable HTTPS IPv6'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Enable HTTPS ssl log'

AUDIT AND ACCOUNTABILITY

Brocade : 'Enable HTTPS'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Enable SFTP IPv4'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Enable SFTP IPv6'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Enable SSH IPv4'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Enable SSH IPv6'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Enable the power-on self-test (POST)'

SYSTEM AND INFORMATION INTEGRITY

Brocade : 'Enable the track changes feature for SNMP traps'

AUDIT AND ACCOUNTABILITY

Brocade : 'Enable the track changes feature'

AUDIT AND ACCOUNTABILITY

Brocade : 'Enforce secure Config Upload/Download'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Enforce signature validation for firmware'

SYSTEM AND INFORMATION INTEGRITY

Brocade : 'Ensure a SSL certificate file is established'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Fabric Configuration Server policy must be rejected'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Fabric Element Authentication must be rejected'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'FIPS Mode is enabled'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'Forward all error logs to syslog daemon'

AUDIT AND ACCOUNTABILITY

Brocade : 'IPfilter policy must be rejected'

SYSTEM AND COMMUNICATIONS PROTECTION

Brocade : 'lockout duration set to 30 minutes'

ACCESS CONTROL

Brocade : 'lockout threshold set to 3'

ACCESS CONTROL

Brocade : 'maximum password age must be set to no more than 60 days'

IDENTIFICATION AND AUTHENTICATION

Brocade : 'minimum length of the password must be set to 9'

IDENTIFICATION AND AUTHENTICATION

Brocade : 'minimum number of lowercase characters set to 1'

IDENTIFICATION AND AUTHENTICATION

Brocade : 'minimum number of numeric digits set to 1'

IDENTIFICATION AND AUTHENTICATION

Brocade : 'minimum number of punctuation characters set to 1'

IDENTIFICATION AND AUTHENTICATION

Brocade : 'minimum number of uppercase characters set to 1'

IDENTIFICATION AND AUTHENTICATION

Brocade : 'minimum password age must be set to at least 30 days'

IDENTIFICATION AND AUTHENTICATION

Brocade : 'password history must be set to 1'

IDENTIFICATION AND AUTHENTICATION

Brocade : 'password warning must be set to at least 30 days'

ACCESS CONTROL

Brocade : 'repeat characters must be set to 1'

IDENTIFICATION AND AUTHENTICATION

Brocade : 'Review admin user listings'

ACCESS CONTROL

Brocade : 'Review Enabled Accounts'

ACCESS CONTROL