User Authentication Security - Restrict commands by job function

Information

Login class configuration is specific to each organization and the Junos OS has many options available to help you design a policy to meet your needs. You will have to experiment with different configurations until you find something that meets your requirements.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Review the system configuration that there are multiple login classes that restrict commands by job function in support of least privilege principle.

See Also

http://www.juniper.net/us/en/training/jnbooks/day-one/fundamentals-series/hardening-junos-devices-checklist/

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(1)

Plugin: Juniper

Control ID: 7b871bdae6df41ab0e5400bdcb30b68108ea7fb7742d35901850c1fc5ccc2427