1.5.1 Set 'no snmp-server' to disable SNMP when unused

Information

If not in use, disable simple network management protocol (SNMP), read and write access.

Rationale:

SNMP read access allows remote monitoring and management of the device.

Solution

Disable SNMP read and write access if not in used to monitor and/or manage device.


hostname(config)#no snmp-server

Impact:

Organizations not using SNMP should require all SNMP services to be disabled by running the 'no snmp-server' command.

References:

http://www.cisco.com/en/US/docs/ios-xml/ios/snmp/command/nm-snmp-cr-book.html

See Also

https://workbench.cisecurity.org/files/2585

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CSCv6|9.1

Plugin: Cisco

Control ID: 7b5344f5c29bbee227b36409ee52e42acc0a11c01cc26281fb5b22d6071a66a5