Security planning
1.2
Defense in depth
16
UM Security BRS-2A
Release
8.7
05/2022
5 Non-default user account
names
1
An attacker must guess or find out the real user account names.
6
Non-default passwords
2
An attacker must guess or find out the real passwords.
7 Specific, restricted
account privileges
An attacker must guess or find out the administrator account
credentials to read privileged data or manipulate device settings.
1. Dedicated user account names can be device-specific and could be deliberately chosen to be non-descriptive.
2. Passwords can be specific to a certain access protocol (for example HTTPS or SNMPv3) and can be device-specific.
ID Barrier Description