SV-77425r1_rule
V-62935
SRG-APP-000090-NDM-000222
RICX-DM-000072
CAT II
10
Configure RiOS permission for auditable events.
Navigate to the device Management Console, then
Navigate to:
Configure >> Security >> User Permissions
Select the user
For "Basic Diagnostics", "TCP Dumps", "Reports". Click the "Deny" attribute
Click "Save" to save these settings permanently
Verify that RiOS restricts permission to select auditable event to authorized administrators.
Navigate to the device Management Console
Navigate to:
Configure >> Security >> User Permissions
Verify the "Deny" attribute is selected for "Basic Diagnostics", "TCP Dumps", "Reports" permissions
If the "Deny" attribute is not set for users who are not authorized access to configure auditable events, this is a finding.
V-62935
False
RICX-DM-000072
Verify that RiOS restricts permission to select auditable event to authorized administrators.
Navigate to the device Management Console
Navigate to:
Configure >> Security >> User Permissions
Verify the "Deny" attribute is selected for "Basic Diagnostics", "TCP Dumps", "Reports" permissions
If the "Deny" attribute is not set for users who are not authorized access to configure auditable events, this is a finding.
M
2931