CIS Cisco IOS XE 17.x v2.2.0 L1

Audit Details

Name: CIS Cisco IOS XE 17.x v2.2.0 L1

Updated: 7/21/2025

Authority: CIS

Plugin: Cisco

Revision: 1.0

Estimated Item Count: 76

File Details

Filename: CIS_Cisco_IOS_XE_17.x_v2.2.0_L1.audit

Size: 197 kB

MD5: e107523faaecd0be2313d663ad4a37e4
SHA256: 7d97b4b7229f4a1f98b35ddf03b56ed5f235d7fbd61005e1cf072bb5e016e3fa

Audit Items

DescriptionCategories
1.1.1 Enable 'aaa new-model'

ACCESS CONTROL

1.1.2 Enable 'aaa authentication login'

ACCESS CONTROL

1.1.3 Enable 'aaa authentication enable default'

ACCESS CONTROL

1.1.4 Set 'login authentication for 'line vty'

ACCESS CONTROL

1.1.5 Set 'login authentication for 'ip http'

ACCESS CONTROL

1.1.6 Set 'aaa accounting' to log all privileged use commands using 'commands 15'

AUDIT AND ACCOUNTABILITY

1.1.7 Set 'aaa accounting connection'

ACCESS CONTROL

1.1.8 Set 'aaa accounting exec'

AUDIT AND ACCOUNTABILITY

1.1.9 Set 'aaa accounting network'

AUDIT AND ACCOUNTABILITY

1.1.10 Set 'aaa accounting system'

AUDIT AND ACCOUNTABILITY

1.2.1 Set 'privilege 1' for local users

IDENTIFICATION AND AUTHENTICATION

1.2.2 Set 'transport input ssh' for 'line vty' connections

IDENTIFICATION AND AUTHENTICATION

1.2.3 Set 'no exec' for 'line aux 0'

CONFIGURATION MANAGEMENT

1.2.4 Create 'access-list' for use with 'line vty'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.2.5 Set 'access-class' for 'line vty'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.2.6 Set 'exec-timeout' to less than or equal to 10 minutes for 'line aux 0'

ACCESS CONTROL

1.2.7 Set 'exec-timeout' to less than or equal to 10 minutes 'line console 0'

ACCESS CONTROL

1.2.8 Set 'exec-timeout' to less than or equal to 10 minutes 'line vty'

ACCESS CONTROL

1.2.9 Set 'http Secure-server' limit

ACCESS CONTROL

1.2.10 Set 'exec-timeout' to less than or equal to 10 min on 'ip http'

SYSTEM AND COMMUNICATIONS PROTECTION

1.3.1 Set the 'banner-text' for 'banner exec'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.2 Set the 'banner-text' for 'banner login'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.3 Set the 'banner-text' for 'banner motd'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.3.4 Set the 'banner-text' for 'webauth banner'

AWARENESS AND TRAINING, PROGRAM MANAGEMENT

1.4.1 Set 'password' for 'enable secret'

ACCESS CONTROL

1.4.2 Enable 'service password-encryption'

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.4.3 Set 'username secret' for all local users

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

1.5.1 Set 'no snmp-server' to disable SNMP when unused

CONFIGURATION MANAGEMENT

1.5.2 Unset 'private' for 'snmp-server community'

CONFIGURATION MANAGEMENT

1.5.3 Unset 'public' for 'snmp-server community'

CONFIGURATION MANAGEMENT

1.5.4 Do not set 'RW' for any 'snmp-server community'

CONFIGURATION MANAGEMENT

1.5.5 Set the ACL for each 'snmp-server community'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.5.6 Create an 'access-list' for use with SNMP

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.5.7 Set 'snmp-server host' when using SNMP

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.5.8 Set 'snmp-server enable traps snmp'

ACCESS CONTROL, SYSTEM AND INFORMATION INTEGRITY

1.5.9 Set 'priv' for each 'snmp-server group' using SNMPv3

IDENTIFICATION AND AUTHENTICATION

1.5.10 Require 'aes 128' as minimum for 'snmp-server user' when using SNMPv3

IDENTIFICATION AND AUTHENTICATION

2.1.1.1.1 Set the 'hostname'

CONFIGURATION MANAGEMENT

2.1.1.1.2 Set the 'ip domain-name'

CONFIGURATION MANAGEMENT

2.1.1.1.3 Set 'modulus' to greater than or equal to 2048 for 'crypto key generate rsa'

SYSTEM AND SERVICES ACQUISITION

2.1.1.1.4 Set 'seconds' for 'ip ssh timeout' for 60 seconds or less

ACCESS CONTROL

2.1.1.1.5 Set maximum value for 'ip ssh authentication-retries'

IDENTIFICATION AND AUTHENTICATION

2.1.1.2 Set version 2 for 'ip ssh version'

CONFIGURATION MANAGEMENT

2.1.2 Set 'no cdp run'

CONFIGURATION MANAGEMENT

2.1.3 Set 'no ip bootp server'

CONFIGURATION MANAGEMENT

2.1.4 Set 'no service dhcp'

CONFIGURATION MANAGEMENT

2.1.5 Set 'service tcp-keepalives-in'

CONFIGURATION MANAGEMENT

2.1.6 Set 'service tcp-keepalives-out'

CONFIGURATION MANAGEMENT

2.1.7 Set 'no service pad'

CONFIGURATION MANAGEMENT

2.2.1 Set 'logging enable'

AUDIT AND ACCOUNTABILITY