Owners Manual

Table Of Contents
Standard Change Management Policies
35
Cisco Event Processing Rules
The event processing rules here typically tie Cisco Compliance Policies with remedial
Cisco Compliance Actions.
Compliance Cisco AAA Login RemediationTriggers a task to configure an AAA
login.
Compliance Cisco BOOTP ServerCorrects PCI Cisco BOOTP Server compliance
failures.
Compliance Cisco CDP ServiceCorrects PCI Cisco CDP Service compliance
failures.
Compliance Cisco Finger ServiceCorrects PCI Cisco Finger Service compliance
failure.
Compliance Cisco HTTP ServerCorrects http server compliance failures.
Compliance Cisco Identd ServiceCorrects PCI Cisco Identd Service compliance
failures.
Compliance Cisco IP Source RouteCorrects PCI Cisco IP Source Route compliance
failures.
Compliance Cisco PAD ServiceCorrects PCI Cisco PAD Service compliance
failures.
Compliance Cisco TCP Small-ServersCorrects PCI Cisco TCP Small-Servers
compliance failures.
Compliance Cisco Timestamps LoggingCorrects PCI Cisco Timestamps Logging
compliance failures.
Compliance Cisco UDP Small-Servers (11.3+)
Juniper Compliance Policies
Packages that support Juniper devices have the following policies:
Juniper FW Filter Private IPRFC 1918
Juniper Policer DNSProtect from source address spoofing
Juniper Policer NTPProtect from source address spoofing
Juniper Policer RADIUSProtect from source address spoofing
Juniper Policer SNMPProtect from source address spoofing
Juniper Policer SSHProtect from source address spoofing
Juniper Policer Small BWProtect from source address spoofing
Juniper Policer TCPProtect from source address spoofing
Juniper Recommended LoggingConfirms recommended logging is on.
Juniper SNMP community NOT public — Checks the SNMP community is not
“public” closing a potential security hole.
Juniper SNMP community NOT private — Checks the SNMP community is not
“private” closing a potential security hole.
Juniper ALL Services PolicyNote: this compliance policy will typically be
modified per deployment.
Juniper Recommended SSHConfirms recommended SSH is on.
Juniper Recommended SyslogConfirms recommended syslogging is on.