Network - IPSec VPN Version Comparison
IPSec VPN Gateway Security Technical Implementation Guide
Comparison
There are 1 differences between versions v1 r14 (Jan. 26, 2018) (the "left" version) and v1 r16 (Jan. 25, 2019) (the "right" version).
Check NET0465 was changed between these two versions. Green, underlined text was added, red, struck-out text was removed.
The regular view of the left check and right check may be easier to read.
Text Differences
Title
Authorized accounts must be assigned the least privilege level necessary to perform assigned duties.
Check Content
Review the accounts authorized for access to the network device. Determine if the accounts are assigned the lowest privilege level necessary to perform assigned duties. User accounts must be set to a specific privilege level which can be mapped to specific commands or a group of commands. Authorized accounts should have the greatest least privilege level unless deemed necessary for assigned duties. If it is determined that authorized accounts are assigned to greater privileges than necessary, this is a finding.
Discussion
By not restricting authorized accounts to their proper privilege level, access to restricted functions may be allowed before authorized personnel are trained or experienced enough to use those functions. Network disruptions or outages may occur due to mistakes made by inexperienced persons using accounts with greater privileges than necessary.
Fix
Configure authorized accounts with the least privilege rule. Each user will have access to only the privileges they require to perform their assigned duties.