Rule ID
SV-266705r1040645_rule
Version
V1R2
CCIs
CCI-002403
Call-home services will routinely send data such as configuration and diagnostic information to the vendor for routine or emergency analysis and troubleshooting. There is a risk that transmission of sensitive data sent to unauthorized persons could result in data loss or downtime due to an attack. (Refer to SRG-NET-000131-RTR-000083.)
Verify the AOS configuration using the web interface: 1. Navigate to Configuration >> System >> More tab. 2. Expand "Phone Home ". If "Phone Home" is enabled, this is a finding.
Configure AOS using the web interface: 1. Navigate to Configuration >> System >> More tab. 2. Expand "Phone Home". 3. Click the toggle button to disable "Phone Home". 4. Click Submit >> Pending Changes >> Deploy Changes.