1.4.1.2 Ensure 'local username and password' is set

Information

Sets a local username and password

Rationale:

Default device configuration does not require strong user authentication enabling unfettered access to an attacker that can reach the device. Creating a local account with a strong password enforces login authentication and provides a fallback authentication mechanism in case remote centralized authentication, authorization and accounting services are unavailable

Solution

Run the following to set a local username and password.

HOSTNAME(CONFIG)#USERNAME _<local_username>_ PASSWORD _<local_password>_ PRIVILEGE _<level> _

The privilege level is chosen between 0 and 15. If the privilege is not configured, the default one is 2.

See Also

https://workbench.cisecurity.org/files/1903

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(2), 800-53|IA-5(1)

Plugin: Cisco

Control ID: b11491a237add1e084aaf3305e8367dba553311c5791db33372c9f907e6dc4a5