The network device must notify the administrator of changes to access and/or privilege parameters of the administrators account that occurred since the last logon.

From Network Device Management Security Requirements Guide

Part of SRG-APP-000079-NDM-000219

Associated with: CCI-000366 CCI-001395

SV-69311r1_rule The network device must notify the administrator of changes to access and/or privilege parameters of the administrators account that occurred since the last logon.

Vulnerability discussion

Providing administrators with information regarding security-related changes to their account allows them to determine if any unauthorized activity has occurred. Changes to the account could be an indication of the account being compromised. Hence, without notification to the administrator, the compromise could go undetected if other controls were not in place to mitigate this risk.

Check content

Determine if the network device notifies the administrator of changes to access and/or privilege parameters of the administrator's account that occurred since the last logon. This requirement may be verified by demonstration, configuration review, or validated test results. This requirement may be met through use of a properly configured authentication server if the device is configured to use the authentication server. If the administrator is not notified of changes to access and/or privilege parameters of the administrator's account that occurred since the last logon, this is a finding.

Fix text

Configure the network device to notify the administrator of changes to access and/or privilege parameters of the administrator's account that occurred since the last logon.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer