STIGUI
V-285611CAT I — High severitySV-285611r1273103_rule

The Content Analysis System (CAS) must enforce Role-Based Access Control (RBAC) to ensure least privilege and protect system configurations, cryptographic settings, and audit records from unauthorized access or modification.

Rule version BCAS-ND-001090 · STIG v1 · 2026-09-16

Discussion

If a network device does not strictly enforce access control policies, a compromised account or an insider threat could gain unrestricted access to the entire system. Without the principle of least privilege and separation of duties, a standard administrator might be able to alter cryptographic keys, modify security policies, or delete audit logs to cover their tracks.

To mitigate this risk, the system must employ RBAC. By mapping authenticated users to specific, restricted roles (such as separating full Administrators from Read-Only viewers), the CAS ensures that users are only granted the specific permissions necessary to perform their assigned duties. This architectural enforcement protects the integrity of audit trails, secures cryptographic modules, and ensures compliance with DoW access control mandates.

Network devices that rely on AAA brokers for authentication and authorization services may need to identify the available security groups or access levels available on the network devices and convey that information to the AAA operator. Once the AAA broker identifies the user persona on the centralized directory service, the user’s security group memberships can be retrieved. The AAA operator may need to create a mapping that links target security groups from the directory service to the appropriate security groups or access levels on the network device. Once these mappings are configured, authorizations can happen dynamically, based on each user’s directory service group membership.

Satisfies: SRG-APP-000033-NDM-000212, SRG-APP-000119-NDM-000236, SRG-APP-000120-NDM-000237, SRG-APP-000121-NDM-000238, SRG-APP-000122-NDM-000239, SRG-APP-000123-NDM-000240, SRG-APP-000133-NDM-000244, SRG-APP-000231-NDM-000271, SRG-APP-000329-NDM-000287, SRG-APP-000340-NDM-000288, SRG-APP-000378-NDM-000302, SRG-APP-000380-NDM-000304, SRG-APP-000408-NDM-000314, SRG-APP-000516-NDM-000335

Check

Verify LDAP group-to-role mappings are configured and match site documentation with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "authentication ldap list-groups". 4. Verify the appropriate group and roles are assigned for authenticated users.

If the group-to-role mappings are missing or do not match site documentation, this is a finding.

Fix

Configure LDAP group-to-role mappings to match site documentation with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and enter the password. 3. Enter "configure terminal". 4. Map the Administrator Group by entering "authentication ldap group [Distinguished Name of the Admin Group]". 5. Enter "role admin". 6. Enter "exit" to return to the config context. 7. Map the Read-Only Viewer Group by entering "authentication ldap group [Distinguished Name of the Viewer Group]". 8. Enter "role read-only". 9. Enter "exit" to return to the config context and then exit configuration mode.

Note: The Distinguished Name (DN) must be the full, exact path to the security group object in the directory (e.g., "CN=CAS_Admins,OU=Security Groups,DC=example,DC=com").

Identifiers

Group ID
V-285611
Group title
SRG-APP-000033-NDM-000212
Rule ID
SV-285611r1273103_rule
Check ID
C-90291r1272950_chk
Fix ID
F-90196r1272951_fix