Owners Manual

Table Of Contents
Standard Change Management Policies
33
Cisco ACL Permit Transit Traffic
Cisco ACL Permit RIP
Cisco ACL Permit OSPF
Cisco ACL Permit IGRP
Cisco ACL Permit EIGRP
Cisco ACL Permit BGP
Cisco ACL Deny access to internal infrastructure
Cisco ACL BGP AS Source
Cisco ACL Anti Spoofing
Cisco ACL - Deny special use address source
Cisco session-timeout' Enabled - ALL LINES
Cisco exec-timeout' enabled ALL LINES
Cisco Proscan Policy Groups
The following combine the ProScan Policies described above into groups to scan for
compliance.
PCI Compliance for CiscoThis includes the following COMPLIANCE policies:
Cisco VTY Transport Input Limit, Cisco VTY Login, Cisco VTY Exec Timeout,
Cisco VTY Access Class Inbound, Cisco SNMP RW Communities, Cisco Password
Encryption, Cisco Finger Service (12.1+), Cisco Finger Service (11.3-12.0), Cisco
Disable NTP, Cisco Identd Service, Cisco AAA Login, Cisco UDP Small-Servers
(11.2-)
HIPPA Compliance for CiscoA policy group. This includes the following
COMPLIANCE policies: Cisco VTY Transport Input Limit, Cisco VTY Login, Cisco
SNMP RW Communities, Cisco Set Login on Console Port, Cisco Password
Encryption, Cisco PAD Service, Cisco HTTP Server, Cisco Enable Secret, Cisco
Timestamps Logging, Cisco NTP Redundant Servers, Cisco Finger Service (11.3-
12.0), Cisco Finger Service (12.1+), Cisco BOOTP Server, Cisco CDP Service.
SOX Compliance for CiscoA policy group. This includes the following
COMPLIANCE policies: Cisco VTY Login, Cisco VTY Transport Input Limit, Cisco
SNMP RW Communities, Cisco Set Login on Console Port, Cisco Password
Encryption, Cisco PAD Service, Cisco Finger Service (11.3-12.0), Cisco Finger
Service (12.1+), Cisco HTTP Server, Cisco Identd Service, Cisco UDP Small-Servers
(11.3+).
NSA Compliance for CiscoA policy group. This includes the following
COMPLIANCE policies: Cisco VTY Login, Cisco VTY Transport Input Limit, Cisco
SNMP RW Communities, Cisco VTY Exec Timeout, Cisco Service Config, Cisco
Password Encryption, Cisco PAD Service, Cisco HTTP Server, Cisco Finger Service
(12.1+), Cisco Finger Service (11.3-12.0), Cisco Enable Secret, Cisco Disable MOP,
Cisco Disable NTP, Cisco NTP Redundant Servers.
CISP Compliance for CiscoA policy group. This includes the following
COMPLIANCE policies: Cisco UDP Small-Servers (11.3+), Cisco VTY Transport
Input Limit, Cisco VTY Login, Cisco VTY Exec Timeout, Cisco VTY Access Class
Inbound, Cisco Password Encryption, Cisco Finger Service (12.1+), Cisco Finger
Service (11.3-12.0), Cisco Enable Secret.