Cisco ISE STIG Checklist
22 items · Security · Hard difficulty · 4 hours
Harden and verify Cisco ISE against the official STIG.
-
Download official Cisco ISE STIG package
Get the latest XCCDF/STIG from the Cyber Exchange or DISA site.
-
Verify ISE software version matches STIG scope
Confirm vendor version and platform are covered by the STIG.
-
Backup current ISE configuration
Export full config and certificates before changes.
-
Apply latest security patches and updates
Install vendor security patches and hotfixes on ISE nodes.
-
Configure NTP to central time source
Point ISE to an authenticated NTP server for accurate logs.
-
Configure Syslog forwarding to central server
Ensure logs are forwarded for centralized auditing.
-
Point ISE to central Syslog server
Set server IP/port and protocol (TCP/UDP/TLS) in ISE settings.
-
Set log severity and retention policy
Configure severity levels and retention consistent with STIG.
-
Enable and configure audit logging
Turn on detailed auditing for admin actions and authentication events.
-
Configure LDAP/AD integration for authentication
Integrate ISE with directory services for user auth and groups.
-
Verify LDAP TLS certificates and trust chains
Ensure secure LDAPS with valid CA-signed certs.
-
Test LDAP bind and role mappings
Validate bind credentials and that group-to-role mapping works.
-
Harden admin accounts and enforce MFA
Require strong passwords, account lockouts, and MFA for admins.
-
Remove or disable default administrative accounts
Eliminate unused default accounts and rename default admin if possible.
-
Restrict management interface access with ACLs or firewall rules
Limit IPs allowed to access GUI, CLI, and API endpoints.
-
Disable unused services and network ports
Turn off services (e.g., unnecessary protocols) to reduce attack surface.
-
Configure certificate management and rotation
Plan and enforce timely renewal of server and trust certificates.
-
Install trusted CA-signed certificates
Replace self-signed certs with CA-signed certs for interfaces.
-
Ensure device profiling and posture policies are enabled and tuned
Verify profiling, posture checks, and remediation flows are active.
-
Test policy enforcement and device compliance
Simulate endpoints to confirm policies block or quarantine noncompliant devices.
-
Run compliance scan using the STIG XCCDF and remediate findings
Execute automated STIG scan, review results, and remediate prioritized issues.
-
Document configuration changes, approvals, and maintenance plan
Record changes, ticket/approval references, and schedule future audits.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.