CIS Cisco Firewall ASA 9 L1 v4.1.0

Audit Details

Name: CIS Cisco Firewall ASA 9 L1 v4.1.0

Updated: 3/7/2023

Authority: CIS

Plugin: Cisco

Revision: 1.17

Estimated Item Count: 93

File Details

Filename: CIS_v4.1.0_Cisco_Firewall_ASA_9_Level_1.audit

Size: 150 kB

MD5: fc6bf0288aaba319efc68cf69889354d
SHA256: 0ca8226e0cba747c7de498f93c7e18a621ea59988e9cf9e3f87764d40a7f22ce

Audit Changelog

 
Revision 1.17

Mar 7, 2023

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.16

Jan 4, 2023

Miscellaneous
  • Metadata updated.
Revision 1.15

Dec 7, 2022

Miscellaneous
  • Variables updated.
Revision 1.14

Apr 25, 2022

Miscellaneous
  • Metadata updated.
Revision 1.13

Mar 29, 2022

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.12

Nov 29, 2021

Functional Update
  • 1.5.1 Ensure 'ASDM banner' is set
Miscellaneous
  • References updated.
Revision 1.11

Jun 17, 2021

Miscellaneous
  • Metadata updated.
  • References updated.
Revision 1.10

Jun 8, 2021

Functional Update
  • 1.1.3 Ensure 'Master Key Passphrase' is set
  • 1.4.2.1 Ensure 'TACACS+/RADIUS' is configured correctly - protocol
  • 1.4.3.1 Ensure 'aaa authentication enable console' is configured correctly
  • 1.4.3.2 Ensure 'aaa authentication http console' is configured correctly
  • 1.4.3.4 Ensure 'aaa authentication serial console' is configured correctly
  • 1.4.3.5 Ensure 'aaa authentication ssh console' is configured correctly
  • 1.4.3.6 Ensure 'aaa authentication telnet console' is configured correctly
  • 1.4.4.1 Ensure 'aaa command authorization' is configured correctly
  • 1.4.5.1 Ensure 'aaa command accounting' is configured correctly
  • 1.4.5.2 Ensure 'aaa accounting for SSH' is configured correctly
  • 1.4.5.3 Ensure 'aaa accounting for Serial console' is configured correctly
  • 1.4.5.4 Ensure 'aaa accounting for EXEC mode' is configured correctly
Miscellaneous
  • Metadata updated.
  • References updated.
Added
  • 1.4.2.1 Ensure 'TACACS+/RADIUS' is configured correctly - host
Removed
  • 1.4.2.1 Ensure 'TACACS+/RADIUS' is configured correctly - server
  • 1.6.3 Ensure 'RSA key pair' is greater than or equal to 2048 bits
  • 3.9 Ensure Botnet protection is enabled for untrusted interfaces
Revision 1.9

Dec 15, 2020

Functional Update
  • 1.1.5 Ensure 'Password Policy' is enabled - lifetime
Revision 1.8

Sep 29, 2020

Miscellaneous
  • References updated.