1.4.1.2 Ensure 'Emergency' account is set

Information

Sets a local username and password for 'Emergency' purposes. This account should only be used for catastrophic failure to the AAA. The password should be kept in a password vault and only accessed in the case of an emergency. After this account is used for the device it is recommended that the password is reset and changed in the password vault.

Rationale:

Default device configuration does not require strong user authentication enabling unfettered access to an attacker that can reach the device. Creating a local account with a strong password enforces login authentication and provides a fallback authentication mechanism in case remote centralized authentication, authorization and accounting services are unavailable

Impact:

While the local name is allowed to be 0-15 with 15 being full admin. It is recommended that the Local account has a complex password and is only used in the event of loss to connection to AAA services.

The best way is to hold the local account password in a secure location.

It is recommended that you change the local account password after every use.

Solution

Run the following to set a local username and password.

hostname(config)#username <local_username> password <local_password> privilege <level>

The privilege level is chosen between 0 and 15. If the privilege is not configured, the default one is 2.

Default Value:

The default username used for the first SSH connection or aaa authentication telnet console is asa but for versions from 8.4(2) and above, there is no default username

See Also

https://workbench.cisecurity.org/benchmarks/7194

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-2, 800-53|IA-5(1), CSCv7|4.4

Plugin: Cisco

Control ID: a8703766222dce661bacbba8d9731a49cae469fa5d0c8c9c954942418e17f719