Information
Disables the password recovery
Rationale:
Disabling the password recovery is an additional physical control. It will prevent an attacker that will have circumvented all the physical safeguards and being in contact with the security appliance to change the existing login password, enable password and local user password and then hack the system.
Solution
Run the following to disable the password recovery:
HOSTNAME (CONFIG)# NO SERVICE PASSWORD-RECOVERY