1.3.1 Ensure 'Image Integrity' is correct

Information

Verifies integrity of an uploaded software before upgrading the system

Rationale:

Sometimes, manipulating software from downloading them from the Cisco.com website to uploading them in the security appliance can modify the software, mostly when the copy has not been properly performed or the software has transited into malware infected machines. For an upgrade to be performed without downtime, the image integrity should be verified.

Solution

Download a new image from the Cisco.com website and apply the audit procedure until obtaining the message 'VERIFIED' at the end of the output.

See Also

https://benchmarks.cisecurity.org/tools2/cisco/CIS_Cisco_Firewall_Benchmark_v4.0.0.pdf