SV-104485r1_rule
V-94655
SRG-APP-000033-NDM-000212
SYMP-NM-000020
CAT I
10
Obtain a list of authorized personnel or host IP addresses and associated roles/privileges. Remove any unauthorized users or excess privileges.
1. Log on to the Web Management Console.
2. Click Configuration >> Policy >> Visual Policy Manager.
3. Click the "Launch" button.
4. Click the "Admin Access" layer.
5. Delete unauthorized users or host IP addresses and adjust or correct user authorizations for "allow read-only" or "allow read-write".
Obtain a list of authorized personnel or host IP addresses and associated roles/privileges. Verify there are no unauthorized users/host IP addresses. Verify there are no users or host IP addresses with excess privileges.
1. Log on to the Web Management Console.
2. Click Configuration >> Policy >> Visual Policy Manager.
3. Click the "Launch" button.
4. Click the "Admin Access" layer.
Verify that any users, hosts, and groups listed in the "source" field of each rule that have an action of "Allow" are authorized administrators with read-write, read-only, or deny.
If users or hosts are configured for excess privileges, this is a finding.
V-94655
False
SYMP-NM-000020
Obtain a list of authorized personnel or host IP addresses and associated roles/privileges. Verify there are no unauthorized users/host IP addresses. Verify there are no users or host IP addresses with excess privileges.
1. Log on to the Web Management Console.
2. Click Configuration >> Policy >> Visual Policy Manager.
3. Click the "Launch" button.
4. Click the "Admin Access" layer.
Verify that any users, hosts, and groups listed in the "source" field of each rule that have an action of "Allow" are authorized administrators with read-write, read-only, or deny.
If users or hosts are configured for excess privileges, this is a finding.
M
3517