2.1.1 Ensure 'Login Banner' is set - message banner on

Information

Configure a login banner, ideally approved by the organization's legal team. This banner should, at minimum, prohibit unauthorized access, provide notice of logging or monitoring, and avoid using the word 'welcome' or similar words of invitation.

Rationale:

Through a properly stated login banner, the risk of unintentional access to the device by unauthorized users is reduced. Should legal action take place against a person accessing the device without authorization, the login banner greatly diminishes a defendant's claim of ignorance.

Solution

Run the following command to enable and set the Banner.
CLI:

Hostname>set message banner on msgvalue 'Organization_Banner'



GUI:

Navigate to System Management > Messages
Checked the Banner message and configured the organization defined banner.

See Also

https://workbench.cisecurity.org/files/2828

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-8a.

Plugin: CheckPoint

Control ID: 910f152acad16fc5efdeda6b4f870aab1371264f26ded6007b659e15dd69a883