1.1.1 Create security user group

Information

This sequence creates a new local user group which can be used for security administrators.

Some organizations have a security officer which has a subset of responsibilities compared to an administrator. A security administrator should be able to view, clear, and copy the security logs on the device.

Solution

Perform the following to determine if the security role is available:

switch# show user-group | include <group>

Impact:

The use of a built-in administrators or operators account for the security officer would provide an excess of access to the device.

See Also

https://workbench.cisecurity.org/benchmarks/24202

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2, CSCv7|4.1

Plugin: ArubaOS

Control ID: 75b2eea6396062a1d0a5a640b096c59edca47c900361c18a1eb29720e4526c48