Below is an example about building compliance policies from the CVEs.
We will be using CVE-2018-0282 for this case.
Creating Policy
(1) Compliance -> (2) Policies -> (3) New -> (4) Name: CVE-2018-0282 -> (4) Save
data:image/s3,"s3://crabby-images/44f54/44f545b9453803568cedf181658241d8599459f8" alt=""
Applying to all vendor Nodes
Under Node Group (1) New -> (2) Name: Cisco_IOS -> (3) Save
data:image/s3,"s3://crabby-images/35faa/35faa11a5466e04bb9d540f7f566112793c45696" alt=""
Creating Rule
If we scroll through the CVE article below is the information we derive:
data:image/s3,"s3://crabby-images/a2ceb/a2cebc6587af1281f6505eb9fbdd3a265c296436" alt=""
So, we would be building rule and condition to identify these lines in the configuration.
Under Rule (1) New -> (2) Name: http_check -> (3) Rule type: Configuration -> (4) Vendor : Cisco_IOS
data:image/s3,"s3://crabby-images/b6e8f/b6e8f1a65832966b77519dac2eafc0c6473dc2fb" alt=""
Under Rule (1) New Logic -> (2) Logic: if A then ( B or C) -> (3) Save
data:image/s3,"s3://crabby-images/acbe5/acbe5bf84c005aa9d1fc9af434733b1b54e172b5" alt=""
Creating Condition:
Define (A) to match the software version that is vulnerable:
Under Condition (1) A -> (2) Type: Software version -> (3) Must contain : 15.5(2) -> (4) Save
data:image/s3,"s3://crabby-images/e35b3/e35b3b43be6b82df3336560604c799589c9b74eb" alt=""
Define B:
This is to match the first line of config lines in the CVE document
(1) B -> (2) Must contain: ip http server -> (3) Save
data:image/s3,"s3://crabby-images/fccd4/fccd45e1ca4e7480fa57c67ec08d8fcbcf66e076" alt=""
Define C
This is to match the next lines of config from the CVE article
(1) C -> (2) Must contain: ip http secure-server -> (3) Save
data:image/s3,"s3://crabby-images/51d64/51d6417964d3b92067eab17b9905f4705447f5ab" alt=""
This completes the creation of the policy.
For testing refer to the article: How to test Compliance Policy
For creating reports refer to the article: How to create Compliance Reports
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article