Cisco ISE STIG Y24M10 Checklist Details (Checklist Revisions)
Supporting Resources:
-
Download Standalone XCCDF 1.1.4 - Cisco ISE STIG
- Defense Information Systems Agency
Target:
Target | CPE Name |
---|---|
Cisco Identity Services Engine | cpe:/a:cisco:identity_services_engine:- (View CVEs) |
Checklist Highlights
- Checklist Name:
- Cisco ISE STIG
- Checklist ID:
- 994
- Version:
- Y24M10
- Type:
- Compliance
- Review Status:
- Final
- Authority:
- Governmental Authority: Defense Information Systems Agency
- Original Publication Date:
- 04/13/2021
Checklist Summary:
The Cisco ISE Security Technical Implementation Guide (STIG) provides the technical security policies, requirements, and implementation details for applying security concepts to the Cisco ISE policy-based network access control platform. Guidance consists of a package of two STIGs that together ensure the secure implementation of the Network Device Management (NDM) function and the Network Access Control (NAC) traffic services. The primary function of the Cisco ISE is to continuously provide a policy decision point that enables enterprises to ensure compliance. Working with other boundary devices (i.e., access switches, wireless LAN controllers [WLCs], Virtual Private Network [VPN] gateways, and data center switches), the ISE gathers information from networks and endpoint device posture to enforce endpoint compliance. Major functions that are in scope include discovery, profiling, policy-based placement, and monitoring of endpoint devices. Per DISA scoping guidance for NAC assessments, functions that were out of scope include guest access and on-device AAA services. Although this product is relatively new, this vendor has a large footprint with DISA’s comply-to-connect initiatives. Audit record generation for the backplane is compliant with STIG requirements by default, and the product offloads the auditing, notifications, authentication, and restriction requirements to the central Syslog and LDAP servers; thus, basic compliance is met with configuration of these services.
Checklist Role:
- Business Productivity Application
Known Issues:
Not provided.
Target Audience:
Parties within the DoD and Federal Government’s computing environments can obtain the applicable STIG from the Cyber Exchange website at https://cyber.mil/. This site contains the latest copies of STIGs, SRGs, and other related security information. Those without a Common Access Card (CAC) that has DoD Certificates can obtain the STIG from https://public.cyber.mil/.
Target Operational Environment:
- Managed
- Specialized Security-Limited Functionality (SSLF)
Testing Information:
Not provided.
Regulatory Compliance:
This document is provided under the authority of DoDI 8500.01.
Comments/Warnings/Miscellaneous:
Not provided.
Disclaimer:
Not provided.
Product Support:
Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil. DISA will coordinate all change requests with the relevant DoD organizations before inclusion in this document. Approved changes will be made in accordance with the DISA maintenance release schedule.
Point of Contact:
disa.stig_spt@mail.mil
Sponsor:
Not provided.
Licensing:
Not provided.
Change History:
updated status to FINAL - 6/4/2021 updated URLs - 10/27/2021 updated URLs - 1/26/2022 Updated resource per DISA - 4/24/22 Updated resource per DISA - 10/27/22 updated URLs - 5/19/2023 updated URLs - 1/26/24 Resource and SHA update 08/06/2024 Updated Version - 08/08/2024 Resource, Title, and SHA Updated - 10/29/2024
Dependency/Requirements:
URL | Description |
---|
References:
Reference URL | Description |
---|