Cisco NX OS Switch STIG Checklist
18 items · Security · Hard difficulty · 4 hours
Step-by-step STIG checklist to secure Cisco NX-OS switches.
-
Download Cisco NX-OS Switch STIG package
Get XCCDF and STIG docs from cyber.mil or public.cyber.mil.
-
Review STIG overview, scope, and components
Identify L2S, RTR, and NDM sections relevant to your devices.
-
Inventory NX-OS devices and map roles
Record model, NX-OS version, location, and management IP.
-
Backup current device configurations
Store backups in encrypted, access-controlled repository.
-
Export running-config to secure storage
Capture running-configs before changes.
-
Save boot-config and verify backups
Save startup-config and confirm restore works.
-
Test STIG changes in lab environment
Validate configuration and service impacts before production.
-
Schedule maintenance window and notify stakeholders
Communicate outages and rollback plan to affected teams.
-
Apply STIG baseline configuration to devices
Push the validated baseline per STIG guidance.
-
Disable unused services and interfaces
Shut down unused ports and turn off unnecessary daemons.
-
Configure AAA and secure management access
Enable TACACS+/RADIUS, SSH only, and role-based access control.
-
Enforce strong SNMP and logging settings
Use SNMPv3, secure community strings, and centralized logging.
-
Set NTP and timezone, and restrict NTP sources
Configure authoritative NTP servers and ACLs for NTP traffic.
-
Apply latest NX-OS firmware and security patches
Verify compatibility and staging before production upgrade.
-
Run DISA STIG compliance scan and generate report
Use XCCDF/OVAL or DISA tools to produce compliance findings.
-
Remediate any remaining findings and re-scan
Address high-severity findings first, then verify fixes.
-
Document deviations, exception waivers, and approvals
Record risk acceptance and approval references for audits.
-
Submit comments or change requests to DISA
Email DISA with feedback: [email protected].
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.