Cisco IOS XR Router STIG (Y26M01) Compliance Checklist
15 items · Security · Hard difficulty · 4 hours
Step-by-step actions to assess and implement the Cisco IOS XR Router STIG.
-
Download the Cisco IOS XR Router STIG package
Get the latest STIG/XCCDF from https://cyber.mil/ or https://public.cyber.mil/.
-
Review the STIG summary and applicability
Confirm covered components (RTR, NDM), role, and scope for your environment.
-
Inventory Cisco IOS XR devices in scope
Create a master list of devices to which the STIG will apply.
-
Record device serials and models
Capture hardware IDs and chassis models for asset tracking.
-
Record software versions and device roles
Log IOS XR versions, feature sets, and device functions.
-
Map STIG controls to each device
Identify which checks apply to specific routers and roles.
-
Assess current compliance using XCCDF or an automated scanner
Run STIG/XCCDF checks or vulnerability scanners to generate findings.
-
Prioritize findings and create a remediation plan
Rank issues by risk and effort; assign owners and timelines.
-
Test remediations in a lab or maintenance window
Validate fixes in a non-production environment before rollout.
-
Apply configuration changes in production per change control
Follow your organization's change management and rollback plans.
-
Patch and update IOS XR to approved versions
Install vendor-approved updates during scheduled maintenance.
-
Harden management plane and administrative access
Restrict admin access, enable AAA, secure remote access, and logging.
-
Validate changes and re-scan for compliance
Re-run automated checks to confirm findings are resolved.
-
Document configurations and update STIG compliance records
Save configs to the repo and record STIG status in compliance logs.
-
Submit comments or change requests to DISA if needed
Send proposed revisions via email to [email protected].
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.