800-53|AC-18(1)

Title

AUTHENTICATION AND ENCRYPTION

Description

The information system protects wireless access to the system using authentication of [Selection (one or more): users; devices] and encryption.

Reference Item Details

Related: SC-13,SC-8

Category: ACCESS CONTROL

Parent Title: WIRELESS ACCESS

Family: ACCESS CONTROL

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.2 Ensure intra-zone traffic is not always allowedFortiGateCIS Fortigate 7.0.x v1.3.0 L1
1.2.1 Ensure 'Domain Name' is setCiscoCIS Cisco ASA 9.x Firewall L1 v1.1.0
1.2.3 Ensure HTTP and Telnet options are disabled for the management interfacePalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.2.4 Ensure HTTP and Telnet options are disabled for all management profiles - HTTPPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.2.4 Ensure HTTP and Telnet options are disabled for all management profiles - TelnetPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.3.2 Ensure 'Image Authenticity' is correctCiscoCIS Cisco ASA 9.x Firewall L1 v1.1.0
1.4.2 Ensure 'Failed Attempts' and 'Lockout Time' for Authentication Profile are properly configured - Failed AttemptsPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.4.2 Ensure 'Failed Attempts' and 'Lockout Time' for Authentication Profile are properly configured - Lockout TimePalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
1.4.3.3 Ensure 'aaa authentication secure-http-client' is configured correctlyCiscoCIS Cisco ASA 9.x Firewall L1 v1.1.0
1.4.4.1 Ensure 'aaa command authorization' is configured correctlyCiscoCIS Cisco ASA 9.x Firewall L1 v1.1.0
1.4.4.2 Ensure 'aaa authorization exec' is configured correctlyCiscoCIS Cisco ASA 9.x Firewall L1 v1.1.0
1.4.5.2 Ensure 'aaa accounting for SSH' is configured correctlyCiscoCIS Cisco ASA 9.x Firewall L1 v1.1.0
2.1.1.1 AuthenticationCiscoCIS Cisco IOS XR 7.x v1.0.0 L2
2.2 Ensure that WMI probing is disabledPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L2
3.1.2 Set 'no ip proxy-arp'CiscoCIS Cisco IOS 12 L2 v4.0.0
3.1.4.3 Use Unicast Routing Protocols OnlyCiscoCIS Cisco NX-OS L2 v1.1.0
3.2 Ensure access to Configuration utility by clients using TLS version 1.2 or laterF5CIS F5 Networks v1.0.0 L1
3.2.4 Disable IP Directed Broadcasts on all Layer 3 InterfacesCiscoCIS Cisco NX-OS L1 v1.1.0
3.3 Ensure access to Configuration utility is restricted to needed IP addresses onlyF5CIS F5 Networks v1.0.0 L1
3.3.1.2 Set 'key'CiscoCIS Cisco IOS XE 17.x v2.1.0 L2
3.3.1.2 Set 'key'CiscoCIS Cisco IOS XE 16.x v2.1.0 L2
3.3.1.3 Set 'key-string'CiscoCIS Cisco IOS XE 17.x v2.1.0 L2
3.3.1.3 Set 'key-string'CiscoCIS Cisco IOS XE 16.x v2.1.0 L2
3.3.1.4 Set 'address-family ipv4 autonomous-system'CiscoCIS Cisco IOS XE 17.x v2.1.0 L2
3.3.1.4 Set 'address-family ipv4 autonomous-system'CiscoCIS Cisco IOS XE 16.x v2.1.0 L2
3.3.1.5 Set 'af-interface default'CiscoCIS Cisco IOS XE 17.x v2.1.0 L2
3.3.1.5 Set 'af-interface default'CiscoCIS Cisco IOS XE 16.x v2.1.0 L2
3.3.1.6 Set 'authentication key-chain'CiscoCIS Cisco IOS XE 17.x v2.1.0 L2
3.3.1.6 Set 'authentication key-chain'CiscoCIS Cisco IOS XE 16.x v2.1.0 L2
3.3.1.7 Set 'authentication mode md5'CiscoCIS Cisco IOS XE 16.x v2.1.0 L1
3.3.1.7 Set 'authentication mode md5'CiscoCIS Cisco IOS XE 17.x v2.1.0 L1
3.3.1.8 Set 'ip authentication key-chain eigrp'CiscoCIS Cisco IOS XE 16.x v2.1.0 L2
3.3.1.8 Set 'ip authentication key-chain eigrp'CiscoCIS Cisco IOS XE 17.x v2.1.0 L2
3.3.1.9 Set 'ip authentication mode eigrp'CiscoCIS Cisco IOS XE 16.x v2.1.0 L2
3.3.1.9 Set 'ip authentication mode eigrp'CiscoCIS Cisco IOS XE 17.x v2.1.0 L2
4.2 Ensure 'Applications and Threats Update Schedule' is set to download and install updates at daily or shorter intervalsPalo_AltoCIS Palo Alto Firewall 9 v1.1.0 L1
4.3.3.1 Ensure autoconf6 is not in useUnixCIS IBM AIX 7 v1.0.0 L1
4.3.3.3 Ensure ndpd-router is not in useUnixCIS IBM AIX 7 v1.0.0 L1
4.7 Ensure to set Strong SSH KEY Exchange algorithmF5CIS F5 Networks v1.0.0 L1
4.8 Ensure access SSH to CLI interface is restricted to needed IP addresses onlyF5CIS F5 Networks v1.0.0 L1
9.2 Ensure KeepAlive Is EnabledUnixCIS Apache HTTP Server 2.4 L1 v2.1.0
9.2 Ensure KeepAlive Is EnabledUnixCIS Apache HTTP Server 2.4 L1 v2.1.0 Middleware
9.3 Ensure MaxKeepAliveRequests is Set to a Value of 100 or GreaterUnixCIS Apache HTTP Server 2.4 L1 v2.1.0
9.3 Ensure MaxKeepAliveRequests is Set to a Value of 100 or GreaterUnixCIS Apache HTTP Server 2.4 L1 v2.1.0 Middleware
9.4 Ensure KeepAliveTimeout is Set to a Value of 15 or LessUnixCIS Apache HTTP Server 2.4 L1 v2.1.0 Middleware
9.4 Ensure KeepAliveTimeout is Set to a Value of 15 or LessUnixCIS Apache HTTP Server 2.4 L1 v2.1.0
10.1 Ensure the LimitRequestLine directive is Set to 512 or lessUnixCIS Apache HTTP Server 2.4 L2 v2.1.0
10.1 Ensure the LimitRequestLine directive is Set to 512 or lessUnixCIS Apache HTTP Server 2.4 L2 v2.1.0 Middleware
10.3 Ensure the LimitRequestFieldsize Directive is Set to 1024 or LessUnixCIS Apache HTTP Server 2.4 L2 v2.1.0
10.3 Ensure the LimitRequestFieldsize Directive is Set to 1024 or LessUnixCIS Apache HTTP Server 2.4 L2 v2.1.0 Middleware