Users Guide
Standard Change Management Policies
34
COMPLIANCE Cisco PAD Service—The packet assembler/disassembler (PAD)
service supports X.25 links. This service is on by default, but it is only needed for
devices using X.25; PCI 2.2.
COMPLIANCE Cisco Service Config—Disable autoloading of configuration files
from a server; PCI 2.2.2
COMPLIANCE Cisco Password Encryption—The password-encryption service
shows user passwords as encrypted strings within the configuration; PCI 8.4
COMPLIANCE Cisco IP Source Route—Disable handling of source routed packets.
COMPLIANCE Cisco SNMP RW Communities—Do not use SNMP Read-Write
strings, and only use Read-Only strings with associated access lists; PCI 2.2.3.
COMPLIANCE Cisco TCP Small-Servers (11.2-)—Disables unneeded TCP services
such as echo, discard, chargen, etc; PCI 2.2.2
COMPLIANCE Cisco TCP Small-Servers (11.3+)—Disables unneeded TCP services
such as echo, discard, chargen, etc; PCI 2.2.2
COMPLIANCE Cisco UDP Small-Servers (11.2-)— Disables unneeded UDP services
such as echo, discard, chargen, etc.; PCI 2.2.2.
COMPLIANCE Cisco UDP Small-Servers (11.3+)—Disables unneeded UDP services
such as echo, discard, chargen, etc; PCI 2.2.2
COMPLIANCE Cisco VTY Exec Timeout—Set Exec Timeout on VTY ports; PCI
8.5.15
COMPLIANCE Cisco VTY Access Class Inbound—Set inbound access class on VTY
ports; PCI 2.2.3.
COMPLIANCE Cisco VTY Login—Enable Login on VTY ports; PCI 2.2.3
COMPLIANCE Cisco VTY Transport Input Limit—Limit Input Transport on VTY
ports; PCI 2.3
COMPLIANCE Cisco Set Login on Console Port—Enable login on console port; PCI
2.2.3
COMPLIANCE Cisco AAA Login—AAA login should be enabled; PCI 8.3
COMPLIANCE Cisco BOOTP Server—The BOOTSP server should be disabled; PCI
2.2.2
COMPLIANCE Cisco CDP Service—Disable CDP (Cisco Discovery Protocol) globally
COMPLIANCE Cisco Console Exec Timeout—Set an exec timeout console port; PCI
8.5.15
Cisco tacacs+ enabled
Cisco monitor logging Enabled
Cisco console logging Enabled
Cisco buffered logging Enabled
Cisco SNMP Community String NOT public
Cisco SNMP Community String NOT private
Cisco RADIUS Enabled
Cisco Interfaces MUST have Description
Cisco Banner Enabled
Cisco ACL RFC 1918 space