Users Guide
Standard Change Management Policies
37
Cisco Event Processing Rules
The event processing rules here typically tie Cisco Compliance Policies with remedial
Cisco Compliance Actions.
Compliance Cisco AAA Login Remediation—Triggers a task to configure an AAA
login.
Compliance Cisco BOOTP Server—Corrects PCI Cisco BOOTP Server compliance
failures.
Compliance Cisco CDP Service—Corrects PCI Cisco CDP Service compliance
failures.
Compliance Cisco Finger Service—Corrects PCI Cisco Finger Service compliance
failure.
Compliance Cisco HTTP Server—Corrects http server compliance failures.
Compliance Cisco Identd Service—Corrects PCI Cisco Identd Service compliance
failures.
Compliance Cisco IP Source Route—Corrects PCI Cisco IP Source Route compliance
failures.
Compliance Cisco PAD Service—Corrects PCI Cisco PAD Service compliance
failures.
Compliance Cisco TCP Small-Servers—Corrects PCI Cisco TCP Small-Servers
compliance failures.
Compliance Cisco Timestamps Logging—Corrects PCI Cisco Timestamps Logging
compliance failures.
Compliance Cisco UDP Small-Servers (11.3+)—
Juniper Compliance Policies
Packages that support Juniper devices have the following policies:
Juniper FW Filter Private IP—RFC 1918
Juniper Policer DNS—Protect from source address spoofing
Juniper Policer NTP—Protect from source address spoofing
Juniper Policer RADIUS—Protect from source address spoofing
Juniper Policer SNMP—Protect from source address spoofing
Juniper Policer SSH—Protect from source address spoofing
Juniper Policer Small BW—Protect from source address spoofing
Juniper Policer TCP—Protect from source address spoofing
Juniper Recommended Logging—Confirms recommended logging is on.
Juniper SNMP community NOT public — Checks the SNMP community is not
“public” closing a potential security hole.
Juniper SNMP community NOT private — Checks the SNMP community is not
“private” closing a potential security hole.
Juniper ALL Services Policy—Note: this compliance policy will typically be
modified per deployment.
Juniper Recommended SSH—Confirms recommended SSH is on.
Juniper Recommended Syslog—Confirms recommended syslogging is on.