NET1660 - The network device must use SNMP Version 3 Security Model with FIPS 140-2 cryptography - 'snmp v3 user'

Information

The network device must use SNMP Version 3 Security Model with FIPS 140-2 validated cryptography for any SNMP agent configured on the device.

SNMP Versions 1 and 2 are not considered secure. Without the strong authentication and privacy that is provided by the SNMP Version 3 User-based Security Model (USM), an unauthorized user can gain access to network management information used to launch an attack against the network.

Solution

If SNMP is enabled, configure the network device to use SNMP Version 3 Security Model with FIPS 140-2 validated cryptography (i.e., SHA authentication and AES encryption).

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Firewall_V8R25_STIG.zip

Item Details

Category: AUDIT AND ACCOUNTABILITY, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AU-9(2), 800-53|SC-13, CAT|I, Rule-ID|SV-3196r4_rule, STIG-ID|NET1660, Vuln-ID|V-3196

Plugin: Cisco

Control ID: 3e8e9ab82100c63f90753e8729124e92905d079f6437b460eac28daff31464b2