SV-258602r961506_rule
V-258602
SRG-APP-000395-NDM-000310
IVCS-NM-000090
CAT II
10
This is applicable if SNMP is enabled. Though the entire SNMP configuration is given to prevent misconfiguration, note that this requirement is focused on the use of v3.
In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.
1. Under "SNMP version data", select v3.
2. Under "Agent Properties", select SNMP Queries.
3. Define the System Name.
4. Define the System Location.
5. Define the System Contact.
6. Under "SNMPv3 Configuration" and "User 1" type the username.
7. Select the "Security Level" of Auth, Priv.
8. Select SHA as the Auth Protocol.
9. Type the Auth password.
10. Select "CFB-AES-128" as the Priv Protocol.
11. Type the Priv password.
12. Under Optional Traps, select "Critical and Major log events".
13. Click "Save Changes".
If SNMP is not used, this is not applicable.
In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.
Under "SNMP version data", verify v2c is not selected.
If the ICS does not use properly configured SNMPv3, this is a finding.
V-258602
False
IVCS-NM-000090
If SNMP is not used, this is not applicable.
In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.
Under "SNMP version data", verify v2c is not selected.
If the ICS does not use properly configured SNMPv3, this is a finding.
M
5558