If the Cisco ISR 4000 Series router uses mandatory access control, the Cisco ISR 4000 Series router must enforce organization-defined mandatory access control policies over all subjects and objects.

From Cisco IOS XE Release 3 NDM Security Technical Implementation Guide

Part of SRG-APP-000491-NDM-000316

Associated with: CCI-000366 CCI-003014

SV-88733r1_rule If the Cisco ISR 4000 Series router uses mandatory access control, the Cisco ISR 4000 Series router must enforce organization-defined mandatory access control policies over all subjects and objects.

Vulnerability discussion

Mandatory access control policies constrain what actions subjects can take with information obtained from data objects for which they have already been granted access, thus preventing the subjects from passing the information to unauthorized subjects and objects. This class of mandatory access control policies also constrains what actions subjects can take with respect to the propagation of access control privileges; that is, a subject with a privilege cannot pass that privilege to other subjects.Enforcement of mandatory access control is typically provided via an implementation that meets the reference monitor concept. The reference monitor enforces (mediates) access relationships between all subjects and objects based on privilege and need to know.The mandatory access control policies are defined uniquely for each network device, so they cannot be specified in the requirement. An example of where mandatory access control may be needed is to prevent administrators from tampering with audit objects.

Check content

Verify that the Cisco ISR 4000 Series router is configured with different privilege levels for different users. The configuration should look like the example below: username USER1 privilege 7 password 7 08751D6D000A061843595F username USER2 privilege 15 password 7 06525E02455D0A16544541 If different privilege levels are not defined, this is a finding.

Fix text

Configure the Cisco ISR 4000 Series router with different privilege levels for different users. The configuration should look similar to the example below: username USER1 privilege 7 password 7 08751D6D000A061843595F username USER2 privilege 15 password 7 06525E02455D0A16544541

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer