Symantec Edge SWG STIG (Y25M11)
18 items · Security · Hard difficulty · 2 hours
Apply the Symantec Edge SWG STIG (Y25M11) with 18 practical security tasks.
-
Download the Symantec Edge SWG STIG and XCCDF
Obtain the Y25M11 STIG and standalone XCCDF from DISA or public Cyber.mil.
-
Confirm device product and firmware match STIG target
Verify CPE/product name and exact software version before applying controls.
-
Apply vendor-released patches and firmware updates
Install the latest Symantec/Broadcom updates to address known vulnerabilities.
-
Restrict administrative access to management interfaces
Limit access to trusted hosts and management VLANs only.
-
Enable role-based access control (RBAC) for administrators
Grant least privilege by assigning only required admin roles.
-
Disable or rename default administrative accounts
Remove or rename factory accounts to reduce attack surface.
-
Enforce multi-factor authentication for admin logins
Require MFA for all privileged accounts accessing management interfaces.
-
Harden management protocols and disable insecure services
Use SSH and HTTPS (TLS); disable Telnet, HTTP, and insecure SNMP versions.
-
Enable and forward logs to a centralized SIEM
Configure secure syslog/CEF and ensure accurate timestamps via NTP.
-
Enable TLS inspection and set decryption policies where required
Implement decryption carefully to balance visibility and privacy needs.
-
Implement web filtering and data loss prevention (DLP) policies
Apply organizational URL categories, file-type controls, and DLP rules.
-
Review and tune URL categories, allowlists, and blocklists
Adjust categories and exceptions to reduce false positives and gaps.
-
Enable malware scanning and sandboxing for file traffic
Activate advanced threat detection and quarantine for suspicious files.
-
Configure secure backups of device configuration
Schedule encrypted backups and store them in an access-controlled location.
-
Harden network access to the device (ACLs, management VLANs)
Use access control lists and dedicated management networks for admin access.
-
Perform vulnerability scanning and remediate critical CVEs
Run scans against the appliance and prioritize fixes for critical findings.
-
Document implemented STIG settings and collect evidence
Record configuration changes, screenshots, and validation output for audits.
-
Schedule periodic STIG reviews and compliance re-validation
Plan quarterly reviews or after significant changes to maintain compliance.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.