Information
Preventing nonprivileged users from executing privileged functions mitigates the risk that unauthorized individuals or processes may gain unnecessary access to information or privileges.
Privileged functions include establishing accounts, performing system integrity checks, or administering cryptographic key management activities. Nonprivileged users are individuals that do not possess appropriate authorizations.
Satisfies: SRG-APP-000340-NDM-000288, SRG-APP-000329-NDM-000287
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Configure the OS10 Switch to assign appropriate user roles or access levels to authenticated users:
OS10(config)# username <name> password ********** role <sysadmin/netoperator/secadmin/netadmin>
Item Details
Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT
References: 800-53|AC-3(7), 800-53|AC-6(10), 800-53|CM-6b., CAT|I, CCI|CCI-000366, CCI|CCI-002169, CCI|CCI-002235, Rule-ID|SV-269790r1051755_rule, STIG-ID|OS10-NDM-000640, Vuln-ID|V-269790
Control ID: cbab29a1008783aaf7748e4d97bbece4a0d5dba2769710cb218b463e306db0b2