SV-215702r521266_rule
V-215702
SRG-APP-000495-NDM-000318
CISC-ND-001240
CAT II
10
Configure the Cisco router to generate log records when account privileges are modified as shown in the example below.
R4(config)#logging userinfo
R4(config)#archive
R4(config-archive)#log config
R4(config-archive-log-cfg)#logging enable
R4(config-archive-log-cfg)#end
Review the Cisco router configuration to verify that it is compliant with this requirement as shown in the examples below.
hostname R4
!
!
logging userinfo
…
…
…
archive
log config
logging enable
Note: The logging userinfo command will log when the administrator increases his or her privilege level while the log config command will log all configuration changes such as changing privilege levels for certain commands.
If the Cisco router is not configured to generate log records when administrator privileges are modified, this is a finding.
V-215702
False
CISC-ND-001240
Review the Cisco router configuration to verify that it is compliant with this requirement as shown in the examples below.
hostname R4
!
!
logging userinfo
…
…
…
archive
log config
logging enable
Note: The logging userinfo command will log when the administrator increases his or her privilege level while the log config command will log all configuration changes such as changing privilege levels for certain commands.
If the Cisco router is not configured to generate log records when administrator privileges are modified, this is a finding.
M
4014