CIS Cisco ASA 9.x Firewall L1 v1.0.0

Audit Details

Name: CIS Cisco ASA 9.x Firewall L1 v1.0.0

Updated: 10/12/2023

Authority: CIS

Plugin: Cisco

Revision: 1.7

Estimated Item Count: 77

File Details

Filename: CIS_Cisco_ASA_9.x_Firewall_v1.0.0_L1.audit

Size: 126 kB

MD5: 1e8ce784b504faaaccfdf9ab14099f07
SHA256: 2be50c27d879ac37ff484ca625934da586d0c42837239b427c7ae2392ecaadbd

Audit Changelog

 
Revision 1.7

Oct 12, 2023

Functional Update
  • 1.10.10 Ensure 'logging trap severity level' is greater than or equal to '5'
  • 1.2.4 Ensure 'Unused Interfaces' is disable
  • 1.3.2 Ensure 'Image Authenticity' is correct
  • 1.4.3.1 Ensure 'aaa authentication enable console' is configured correctly
  • 1.4.3.2 Ensure 'aaa authentication http console' is configured correctly
  • 1.4.3.4 Ensure 'aaa authentication serial console' is configured correctly
  • 1.4.3.5 Ensure 'aaa authentication ssh console' is configured correctly
  • 1.4.4.1 Ensure 'aaa command authorization' is configured correctly
  • 1.4.4.2 Ensure 'aaa authorization exec' is configured correctly
  • 1.4.5.1 Ensure 'aaa accounting command' is configured correctly
  • 1.4.5.2 Ensure 'aaa accounting for SSH' is configured correctly
  • 1.4.5.3 Ensure 'aaa accounting for Serial console' is configured correctly
  • 1.4.5.4 Ensure 'aaa accounting for EXEC mode' is configured correctly
  • 1.6.1 Ensure 'SSH source restriction' is set to an authorized IP address
  • 1.7.3 Ensure 'SSL AES 256 encryption' is set for HTTPS access
  • 1.9.1.2 Ensure 'NTP authentication key' is configured correctly
Informational Update
  • 1.2.4 Ensure 'Unused Interfaces' is disable
Miscellaneous
  • Metadata updated.
  • Variables updated.
Added
  • 1.11.4 Ensure 'SNMP traps' is enabled
Removed
  • 1.11.4 Ensure 'SNMP traps' is enabled - authentication
  • 1.11.4 Ensure 'SNMP traps' is enabled - coldstart
  • 1.11.4 Ensure 'SNMP traps' is enabled - linkdown
  • 1.11.4 Ensure 'SNMP traps' is enabled - linkup
Revision 1.6

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.5

Jan 4, 2023

Miscellaneous
  • Metadata updated.
  • Variables updated.
Revision 1.4

Dec 7, 2022

Miscellaneous
  • Metadata updated.
Revision 1.3

Apr 25, 2022

Miscellaneous
  • Metadata updated.
Revision 1.2

Mar 29, 2022

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.1

Nov 29, 2021

Functional Update
  • 1.5.1 Ensure 'ASDM banner' is set
Miscellaneous
  • References updated.