Cisco IOS XE Switch STIG (Y26M01)
23 items · Security · Hard difficulty · 4 hours
Practical steps to apply the Cisco IOS XE Switch STIG and verify compliance.
-
Download STIG package from DoD Cyber Exchange
Get the XCCDF/STIG from https://cyber.mil/ (public.cyber.mil if no CAC).
-
Review STIG summary and scope
Read the STIG overview to determine coverage and modules (L2S, RTR, NDM).
-
Inventory Cisco IOS XE switches in scope
List device hostnames, models, IOS XE versions, and locations.
-
Verify device model and IOS XE version
Confirm each device model and software match STIG applicability.
-
Identify applicable STIG modules (L2S, RTR, NDM)
Map each device to the relevant STIG module(s) before changes.
-
Schedule maintenance window for changes
Coordinate downtime, notify stakeholders, and prepare rollback plans.
-
Backup current device configurations
Export running/startup configs and save device images before making changes.
-
Configure secure management
Apply STIG management hardening (authentication, encryption, access control).
-
Enable SSH and disable Telnet
Require SSH v2 for remote management and remove Telnet access.
-
Configure AAA with TACACS+/RADIUS and role-based access
Use centralized auth and least-privilege roles for administrative access.
-
Disable HTTP server and enable HTTPS where needed
Turn off insecure HTTP; enable HTTPS with valid certs if web UI required.
-
Disable unused services and interfaces
Shut down unused ports and disable unnecessary protocols (CDP, LLDP if not used).
-
Implement time sync and logging (NTP, syslog)
Configure reliable NTP sources and forward logs to a secure syslog server.
-
Apply and verify strong password and account policies
Enforce complexity, aging, and lockout policies as per STIG guidance.
-
Configure ACLs to restrict management access
Limit SSH/HTTPS and SNMP access to trusted admin networks only.
-
Enable secure boot and firmware verification
Turn on image integrity checks and secure boot features where supported.
-
Apply STIG-recommended configurations and hardening
Implement specific settings from the XCCDF/STIG package for each device.
-
Test configurations in a lab or pilot group
Validate functionality and rollback procedures before wide deployment.
-
Deploy configurations to production during maintenance
Apply changes during the approved window and monitor for issues.
-
Perform vulnerability scan and compliance check
Use automated tools to verify STIG compliance and detect CVEs.
-
Document compliance evidence and exceptions
Collect configs, scans, test results, and document any accepted deviations.
-
Submit comments or change requests to DISA via email
Send feedback or proposed revisions to [email protected].
-
Schedule regular patching and monitoring
Plan ongoing updates, log reviews, and periodic STIG revalidation.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.