1.5.1 Set 'no snmp-server' to disable SNMP when unused

Information

If not in use, disable simple network management protocol (SNMP), read and write access.

Rationale:

SNMP read access allows remote monitoring and management of the device.

Impact:

Organizations not using SNMP should require all SNMP services to be disabled by running the 'no snmp-server' command.

Solution

Disable SNMP read and write access if not in used to monitor and/or manage device.

hostname(config)#no snmp-server

See Also

https://workbench.cisecurity.org/benchmarks/12741

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: Cisco

Control ID: c80aba4f50fc0ec33adde4f4e6c9d56712aa0e333f3d7df29ba0422714a4c310