Security certifications compliance characteristics
This table describes changes to system behaviors and compliance characteristics when CC (Common Criteria) or UCAPL (Unified Capabilities Approved Product List) mode is enabled. Restrictions on login accounts apply to command line access. These restrictions do not apply to web interface access.
|
System Change |
Cloud-Delivered Firewall Management Center |
Classic Managed Devices |
Secure Firewall Threat Defense |
|||
|---|---|---|---|---|---|---|
|
CC Mode |
UCAPL Mode |
CC Mode |
UCAPL Mode |
CC Mode |
UCAPL Mode |
|
|
FIPS compliance is enabled. |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
The system does not allow remote storage for backups or reports. |
Yes |
Yes |
— |
— |
— |
— |
|
The system starts an additional system audit daemon. |
No |
Yes |
No |
Yes |
No |
No |
|
The system boot loader is secured. |
No |
Yes |
No |
Yes |
No |
No |
|
The system applies additional security to login accounts. |
No |
Yes |
No |
Yes |
No |
No |
|
The system disables the reboot key sequence Ctrl+Alt+Del. |
No |
Yes |
No |
Yes |
No |
No |
|
The system enforces a maximum of ten simultaneous login sessions. |
No |
Yes |
No |
Yes |
No |
No |
|
Passwords must be at least 15 characters long, and must consist of alphanumeric characters of mixed case and must include at least one numeric character. |
No |
Yes |
No |
Yes |
No |
No |
|
The minimum required password length for the local |
— |
— |
No |
No |
Yes |
Yes |
|
The minimum required password length for the local |
No |
No |
No |
No |
Yes |
Yes |
|
Passwords cannot be a word that appears in a dictionary or include consecutive repeating characters. |
No |
Yes |
No |
Yes |
No |
No |
|
The system locks out users other than |
No |
Yes |
No |
Yes |
No |
No |
|
The system stores password history by default. |
No |
Yes |
No |
Yes |
No |
No |
|
The |
Yes |
Yes |
Yes |
Yes |
— |
— |
|
The |
— |
— |
Yes, regardless of security certifications compliance enablement. |
Yes, regardless of security certifications compliance enablement. |
Yes |
Yes |
|
The |
No |
No |
Yes, regardless of security certifications compliance enablement. |
Yes, regardless of security certifications compliance enablement. |
Yes |
Yes |
|
The system automatically rekeys an SSH session with an appliance:
|
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |
|
The system performs a file system integrity check (FSIC) at boot-time. If the FSIC fails, Secure Firewall software does not start, remote SSH access is disabled, and you can access the appliance only via local console. If this happens, contact Cisco TAC. |
Yes |
Yes |
Yes |
Yes |
Yes |
Yes |