The Riverbed NetProfiler must be configured to use an authentication server to authenticate users prior to granting administrative access.
DISA Rule
SV-256093r997791_rule
Vulnerability Number
V-256093
Group Title
SRG-APP-000516-NDM-000336
Rule Version
RINP-DM-000060
Severity
CAT I
CCI(s)
- CCI-000366 - Implement the security configuration settings.
- CCI-000370 - Manage configuration settings for organization-defined system components using organization-defined automated mechanisms.
- CCI-003627 - Disable accounts when the accounts have expired.
- CCI-003628 - Disable accounts when the accounts are no longer associated to a user.
- CCI-004046 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
- CCI-004047 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that the device meets organization-defined strength of mechanism requirements.
Weight
10
Fix Recommendation
This requirement does not apply to the local account of last resort or system accounts.
Go to Administration >> Account Management >> Remote Authentication.
Configure and enable RADIUS, TACACS+, or SAML 2.0.
The following is an example using RADIUS. Refer to the user's guide for instructions for TACACS+ or SAML.
Check Contents
Go to Administration >> Account Management >> Remote Authentication.
Verify that RADIUS, TACACS+, or SAML 2.0 are enabled and configured.
If this is not true, this is a finding.
Vulnerability Number
V-256093
Documentable
False
Rule Version
RINP-DM-000060
Severity Override Guidance
Go to Administration >> Account Management >> Remote Authentication.
Verify that RADIUS, TACACS+, or SAML 2.0 are enabled and configured.
If this is not true, this is a finding.
Check Content Reference
M
Target Key
5514