STIGQter STIGQter: STIG Summary: Dell OS10 Switch NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 10 Dec 2024:

The Dell OS10 Switch must be configured to assign appropriate user roles or access levels to authenticated users.

DISA Rule

SV-269769r1052474_rule

Vulnerability Number

V-269769

Group Title

SRG-APP-000033-NDM-000212

Rule Version

OS10-NDM-000100

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the OS10 Switch to assign appropriate user roles or access levels to authenticated users.

OS10(config)# username <name> password ********** role <sysadmin/netoperator/secadmin/netadmin>

Check Contents

If the network device is configured to use a AAA service account, and the AAA broker is configured to assign authorization levels based on centralized user account group memberships on behalf of the network device, that will satisfy this requirement. Because the responsibility for meeting this requirement is transferred to the AAA broker, this requirement is not applicable for the local network device. This requirement may be verified by demonstration or configuration review.

Verify the Dell OS10 Switch is configured to assign appropriate user roles to authenticated users. Valid roles are system admin, security admin, network admin, and network operator. Verify the correct role is assigned to each user.

OS10# show running-configuration users
username admin password **** role sysadmin priv-lvl 15
username op100 password **** role netoperator priv-lvl 1
OS10#

If any users are assigned to the wrong role, this is a finding.

Vulnerability Number

V-269769

Documentable

False

Rule Version

OS10-NDM-000100

Severity Override Guidance

If the network device is configured to use a AAA service account, and the AAA broker is configured to assign authorization levels based on centralized user account group memberships on behalf of the network device, that will satisfy this requirement. Because the responsibility for meeting this requirement is transferred to the AAA broker, this requirement is not applicable for the local network device. This requirement may be verified by demonstration or configuration review.

Verify the Dell OS10 Switch is configured to assign appropriate user roles to authenticated users. Valid roles are system admin, security admin, network admin, and network operator. Verify the correct role is assigned to each user.

OS10# show running-configuration users
username admin password **** role sysadmin priv-lvl 15
username op100 password **** role netoperator priv-lvl 1
OS10#

If any users are assigned to the wrong role, this is a finding.

Check Content Reference

M

Target Key

5666