SV-242659r720805_rule
V-242659
SRG-APP-000231-NDM-000271
CSCO-NM-000540
CAT I
10
Create a local web-based administrator. ONLY one web-based admin account should exist on the local device. The default CLI account is also local and cannot be removed.
1. Choose Administration >> System >> Admin Access >> Administrators >> Admin Users >> Add.
2. From the drop-down, choose "Create an Admin User".
3. Enter the admin name and other information.
4. Add the Super User group.
5. Click "Submit".
View the local admin users.
1. Choose Administration >> System >> Admin Access >> Administrators >> Admin Users >>View.
2. Verify there are only two local accounts are defined. Both must be in the Super User group. These users must be the web-based Account of Last Resort and the default CLI admin user.
If the Cisco ISE has unauthorized local users defined, this is a finding.
V-242659
False
CSCO-NM-000540
View the local admin users.
1. Choose Administration >> System >> Admin Access >> Administrators >> Admin Users >>View.
2. Verify there are only two local accounts are defined. Both must be in the Super User group. These users must be the web-based Account of Last Resort and the default CLI admin user.
If the Cisco ISE has unauthorized local users defined, this is a finding.
M
5384