6.6.8 Ensure login message is set

Information

A login message should be displayed before a user logs into the router.

Rationale:

Prior to a user logging into the router a legal notice should be displayed warning that they are connecting to a private system.

This legal notice may be necessary to protect your organizations rights to pursue legal action or to monitor users of the system. It might, in general:

Warn that this is a private system

Tell unauthorized users that they should disconnect immediately

Inform users that activity is monitored/recorded and may be shared with 3rd parties or used in a criminal investigation

May reference applicable legislation

May specify that continuing to login constitutes agreement to an Acceptable Use policy or similar

May provide contact details for any queries

NOTE The wording of the legal notice is normally defined as part of an organization's security policy. You should consult your organizations legal department or counsel to ensure the legality of the banner message and suitability for the country/s in which you operate.

Solution

Configure a login message using the following command under the [edit system] hierarchy:

[edit system]
user@host#set login message '<LEGAL NOTICE>'

Default Value:

By default no login message is set.

See Also

https://workbench.cisecurity.org/files/3069

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2, CSCv7|16

Plugin: Juniper

Control ID: 2daea5ed03800a420e2037eaa7f5c18ba6081ee6abad4c7a15354868edd96f39