The Cisco ACI must not be configured to have any feature enabled that calls home to the vendor.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-272076 | CACI-RT-000016 | SV-272076r1168127_rule | CCI-002403 | medium |
| Description | ||||
| Call home services will routinely send data such as configuration and diagnostic information to the vendor for routine or emergency analysis and troubleshooting. There is a risk that transmission of sensitive data sent to unauthorized persons could result in data loss or downtime due to an attack. | ||||
| STIG | Date | |||
| Cisco ACI Router Security Technical Implementation Guide | 2025-12-11 | |||
Related Frameworks
2 paths across 2 frameworks
Related Frameworks
NIST 800-531 mapping
SC-7(11)
1.00
- DISA · V1R2 · disa_xccdf · related
- DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-002403
1.00
- DISA · V1R2 · disa_xccdf · related
Details
Check Text (C-272076r1168127_chk)
Verify the ACI configuration under Admin >> External Data Collectors >> monitoring Destinations >> smart callhome/callhome is not setup, and that no Intersight configuration is setup at System >> System Settings >> Intersight Connectivity.
If the Call Home feature is configured to send messages to unauthorized individuals such as Cisco TAC, this is a finding.
Fix Text (F-76033r1168126_fix)
Disable the Call Home feature:
1. Navigate to Admin >> External Data Collectors >> monitoring Destinations >> smart callhome.
2. In the General tab, set the Admin State to "Off".
3. Click "Save".