STIGUI
V-285618CAT I — High severitySV-285618r1274301_rule

The Content Analysis System (CAS) must disable nonsecure ports, protocols, and services to prevent unauthorized access and protect the integrity of the system.

Rule version BCAS-ND-001325 · STIG v1 · 2026-09-16

Discussion

Authentication for administrative (privileged level) access to the device is required at all times. An account can be created on the device's local database for use when the authentication server is down or connectivity between the device and the authentication server is not operable. This account is referred to as the account of last resort since it is intended to be used as a last resort and when immediate administrative access is absolutely necessary.

The account of last resort logon credentials must be stored in a sealed envelope and kept in a safe. The safe must be periodically audited to verify the envelope remains sealed. The signature of the auditor and the date of the audit should be added to the envelope as a record. Administrators should secure the credentials and disable the root account (if possible) when not needed for system administration functions.

Check

Verify CAS does not have any unnecessary or nonsecure ports, protocols, and services enabled with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "show running-config". 4. Review the running configuration. For example, the following commands/settings should not be present or active:

"web-management http enable" (HTTP web management active) "agent version v1" or "agent version v2c" under the SNMP configuration "protocol TCP" or "protocol UDP" under syslog-alerts (unless "protocol TLS" is used) "encryption type none" under the SMTP email-alerts settings "authentication rest-api-key" (active, undocumented REST API keys)

If any unnecessary or nonsecure ports, protocols, or services are enabled, this is a finding.

Fix

Configure the system to disable nonsecure ports, protocols, and services with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable", enter the password, and enter "configure terminal". 3. Disable unencrypted HTTP web management by entering "web-management http disable". 4. Disable legacy SNMP protocols and enforce SNMPv3 by entering "snmp" and then "agent version v3". 5. Disable plaintext syslog forwarding and enforce TLS by entering "alerts syslog-alerts servers [HOSTNAME] protocol TLS". 6. Remove any active, undocumented REST API keys by entering "authentication rest-api-key delete [ID]". (Replace [ID] with the key identifier.) 7. Enter "exit" and then "exit" again to leave configuration mode.

Identifiers

Group ID
V-285618
Group title
SRG-APP-000142-NDM-000245
Rule ID
SV-285618r1274301_rule
Check ID
C-90298r1272971_chk
Fix ID
F-90203r1274300_fix