Cisco IOS XE Router STIG (Y26M01) — Compliance Checklist
22 items · Security · Hard difficulty · 2 hours
Actionable STIG tasks to harden and validate Cisco IOS XE routers.
-
Download latest STIG and SCAP content
Get DISA XCCDF/SCAP content and the IOS XE RTR/NDM STIG package.
-
Review README and STIG change history
Read README and change logs for tool-specific instructions and updates.
-
Inventory affected IOS XE devices
List device models, hostnames, IPs, and administrative owners.
-
Verify device firmware and IOS XE version
Record current images and note required security patches.
-
Schedule maintenance window
Coordinate downtime with stakeholders before changes.
-
Backup device configurations
Save configs offline and to a versioned repository before changes.
-
Apply IOS XE security patches and updates
Install vendor-recommended security fixes and reboot if required.
-
Disable unused services
Turn off services like HTTP, finger, and others not required.
-
Configure secure management
Harden how administrators access and manage the device.
-
Enable SSH v2 and restrict management protocols
Ensure SSH v2 is configured and limit protocol exposure.
-
Disable Telnet and HTTP management interfaces
Remove insecure remote management methods and use secure alternatives.
-
Configure AAA and centralized authentication
Use TACACS+/RADIUS for admin authentication and accounting.
-
Enforce strong password and account policies
Set complexity, expiration, lockout, and remove default accounts.
-
Configure logging and forward to remote syslog
Enable logging, set levels, and send logs to a centralized collector.
-
Configure NTP and secure time synchronization
Point to trusted NTP servers and restrict NTP access.
-
Harden SNMP (use SNMPv3 and limit access)
Disable SNMP v1/v2, enable v3 with auth/privacy, and restrict hosts.
-
Implement management-plane ACLs and limit admin access
Restrict administrative interfaces to management subnets only.
-
Run automated STIG scan (SCC/XCCDF/SCAP)
Use DISA-provided SCAP/XCCDF content or SCC tools for scanning.
-
Review scan results and remediate findings
Prioritize and track remediation for high-severity findings.
-
Document configuration changes and approvals
Record change tickets, approvals, and configuration diffs.
-
Archive configs, STIG artifacts, and reports
Store scans, STIG files, and backups for audit retention.
-
Subscribe to DISA updates and send comments to DISA email
Monitor DISA releases and send feedback to [email protected].
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.