STIGQter STIGQter: STIG Summary: Cisco ACI NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must automatically audit account creation.

DISA Rule

SV-271939r1114173_rule

Vulnerability Number

V-271939

Group Title

SRG-APP-000026-NDM-000208

Rule Version

CACI-ND-000024

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To change the logging level to 6:
1. Select a service from the "Services" field in the "Changing Logging Level" window.
2. Choose the new logging level for the service from the "Logging Level" field.
3. Click "Apply".

Check Contents

View the AAA event types in the local log:
1. In the menu bar, click "Admin".
2. In the submenu bar, click "AAA".
3. In the Navigation pane, choose "AAA Authentication".
4. In the Work pane, click the "History" tab.
5. Under the History tab, click the "Events" subtab to view the event log.
6. Under the History tab, click the "Audit Log" subtab to view the audit log.
7. Double-click a log entry to view additional details about the event.

If account change actions are not being logged, this is a finding.

Vulnerability Number

V-271939

Documentable

False

Rule Version

CACI-ND-000024

Severity Override Guidance

View the AAA event types in the local log:
1. In the menu bar, click "Admin".
2. In the submenu bar, click "AAA".
3. In the Navigation pane, choose "AAA Authentication".
4. In the Work pane, click the "History" tab.
5. Under the History tab, click the "Events" subtab to view the event log.
6. Under the History tab, click the "Audit Log" subtab to view the audit log.
7. Double-click a log entry to view additional details about the event.

If account change actions are not being logged, this is a finding.

Check Content Reference

M

Target Key

5682