Security
How to read a device's management access posture
Management exposure is not one setting. It is the sum of which services answer, whether they are encrypted, whether they are confined to a management VRF, whether logging in is authenticated centrally, and whether an idle session ever closes. Read individually those checks look like housekeeping. Read together for one device they describe how someone would get in, and that is the reading worth learning.
Before you start
What you need
- Module required: compliance.
- Permission required: view_audit.
- All benchmarked platforms; check names and counts differ by vendor
1. Open the worst-scoring device

2. Read the checks together

3. Follow it to the terminal lines

The limits
What this view does not tell you
- A benchmark is a shipped opinion about a platform, not your organisation's policy. A device that deliberately runs a service your standard permits will still be reported as failing until the check is waived.
- Check counts are not comparable between vendors. One platform's benchmark may run thirty checks and another sixty, so a lower score does not automatically mean a worse device - compare a device against its own platform's baseline.
