1.7.3 Ensure 'SSL AES 256 encryption' is set for HTTPS access

Information

Sets the SSL encryption algorithm to AES 256

Rationale:

Given that the network may be prone to sniffing, the HTTP access to the security appliance must be secured with SSL or TLS protocols. A secure encryption algorithm must be used.

Solution

For version 9.x, run the following command to enable AES 256 algorithm

hostname(config)# ssl cipher tlsv1.2 custom AES256-SHA

See Also

https://workbench.cisecurity.org/benchmarks/7194

Item Details

Category: CONFIGURATION MANAGEMENT, MAINTENANCE

References: 800-53|CM-7, 800-53|MA-4, CSCv7|14.4

Plugin: Cisco

Control ID: 7392085ab772f3c54c7b13998ed3261c239851bf02d70934e2be247a58640ad5