U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cisco ISE STIG Y24M01 Checklist Details (Checklist Revisions)

Supporting Resources:

Target:

Target CPE Name
Cisco Identity Services Engine cpe:/a:cisco:identity_services_engine:- (View CVEs)

Checklist Highlights

Checklist Name:
Cisco ISE STIG
Checklist ID:
994
Version:
Y24M01
Type:
Compliance
Review Status:
Final
Authority:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:
04/13/2021

Checklist Summary:

The Cisco ISE Security Technical Implementation Guide (STIG) provides the technical security policies, requirements, and implementation details for applying security concepts to the Cisco ISE policy-based network access control platform. Guidance consists of a package of two STIGs that together ensure the secure implementation of the Network Device Management (NDM) function and the Network Access Control (NAC) traffic services. The primary function of the Cisco ISE is to continuously provide a policy decision point that enables enterprises to ensure compliance. Working with other boundary devices (i.e., access switches, wireless LAN controllers [WLCs], Virtual Private Network [VPN] gateways, and data center switches), the ISE gathers information from networks and endpoint device posture to enforce endpoint compliance. Major functions that are in scope include discovery, profiling, policy-based placement, and monitoring of endpoint devices. Per DISA scoping guidance for NAC assessments, functions that were out of scope include guest access and on-device AAA services. Although this product is relatively new, this vendor has a large footprint with DISA’s comply-to-connect initiatives. Audit record generation for the backplane is compliant with STIG requirements by default, and the product offloads the auditing, notifications, authentication, and restriction requirements to the central Syslog and LDAP servers; thus, basic compliance is met with configuration of these services.

Checklist Role:

  • Business Productivity Application

Known Issues:

Not provided.

Target Audience:

Parties within the DoD and Federal Government’s computing environments can obtain the applicable STIG from the Cyber Exchange website at https://cyber.mil/. This site contains the latest copies of STIGs, SRGs, and other related security information. Those without a Common Access Card (CAC) that has DoD Certificates can obtain the STIG from https://public.cyber.mil/.

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Not provided.

Regulatory Compliance:

This document is provided under the authority of DoDI 8500.01.

Comments/Warnings/Miscellaneous:

Not provided.

Disclaimer:

Not provided.

Product Support:

Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil. DISA will coordinate all change requests with the relevant DoD organizations before inclusion in this document. Approved changes will be made in accordance with the DISA maintenance release schedule.

Point of Contact:

disa.stig_spt@mail.mil

Sponsor:

Not provided.

Licensing:

Not provided.

Change History:

updated status to FINAL - 6/4/2021
updated URLs - 10/27/2021
updated URLs - 1/26/2022
Updated resource per DISA - 4/24/22
Updated resource per DISA - 10/27/22
updated URLs - 5/19/2023
updated URLs - 1/26/24

Dependency/Requirements:

URL Description

References:

Reference URL Description

NIST checklist record last modified on 01/26/2024