{"id":17343,"date":"2026-09-06T17:13:04","date_gmt":"2026-09-06T17:13:04","guid":{"rendered":"https:\/\/dmsretail.com\/RetailNews\/cisco-and-the-disa-stig-turning-zero-trust-policy-into-repeatable-practice-part-1-cisco-ise\/"},"modified":"2026-09-06T17:13:04","modified_gmt":"2026-09-06T17:13:04","slug":"cisco-and-the-disa-stig-turning-zero-trust-policy-into-repeatable-practice-part-1-cisco-ise","status":"publish","type":"post","link":"https:\/\/dmsretail.com\/RetailNews\/cisco-and-the-disa-stig-turning-zero-trust-policy-into-repeatable-practice-part-1-cisco-ise\/","title":{"rendered":"Cisco and the DISA STIG: Turning Zero Trust Policy into Repeatable Practice &#8211; Part 1: Cisco ISE"},"content":{"rendered":"<p> <p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/>\n<\/p>\n<div>\n<p><em><span class=\"EOP Selected SCXW225929775 BCX0\" data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">co-authored by <span class=\"TextRun SCXW94385754 BCX0\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW94385754 BCX0\">Jim Kotantoulas<\/span><span class=\"NormalTextRun SCXW94385754 BCX0\">, DoD Cisco Security Engineer<\/span><\/span><span class=\"EOP SCXW94385754 BCX0\" data-ccp-props=\"{&quot;335551550&quot;:3,&quot;335551620&quot;:3,&quot;335559739&quot;:0}\">\u00a0<\/span><\/span><\/em><\/p>\n<p><span data-contrast=\"auto\">For U.S. Department of\u00a0Defense\u00a0organizations, security policy only creates value when it can be translated into consistent technical practice. That is why Security Technical Implementation Guides, or STIGs, matter: they turn cybersecurity requirements into configuration and assessment criteria that administrators, assessors, and authorizing officials can apply in operational environments.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The Defense Information Systems Agency\u00a0(DISA)\u00a0has published an updated Security Technical Implementation Guide for Cisco Identity Services Engine. The Cisco ISE STIG Version 2, Release 4, dated\u00a0<\/span><b><span data-contrast=\"auto\">July 1, 2026<\/span><\/b><span data-contrast=\"auto\">, was developed by Cisco Systems and DISA for the Department of Defense. It gives DoD teams a repeatable baseline for reviewing how Cisco ISE is configured to protect its own management plane and perform its network access control mission.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">For organizations already using Cisco ISE as a policy decision point, the guide provides more than a compliance checklist. It connects security policy to practical controls for\u00a0identifying\u00a0endpoints, evaluating posture, making authorization decisions, restricting noncompliant devices, and producing the audit evidence needed to support ongoing risk management.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">One package, two essential security perspectives<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">The Cisco ISE STIG package\u00a0contains\u00a0two complementary benchmarks:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Cisco ISE Network Access Control (NAC) STIG: Focuses on the policies and services Cisco ISE uses to evaluate endpoints and control access to the network. The Version 2, Release 4 benchmark\u00a0contains\u00a030 requirements.<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Cisco ISE Network Device Management (NDM) STIG: Focuses on securely administering and\u00a0operating\u00a0the Cisco ISE\u00a0platform itself. The Version 2, Release 4 benchmark\u00a0contains\u00a051 requirements.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">Together, the two benchmarks\u00a0contain\u00a081 checks. The STIG overview\u00a0states\u00a0that both the NAC and NDM guides are\u00a0required\u00a0for a Cisco ISE security review. That distinction is important. An organization cannot evaluate only the access decisions made by Cisco ISE while overlooking the security of the system making those decisions. Strong policy enforcement depends on a well-protected management\u00a0plane, trusted administrative access, reliable time and logging, supported software, secure protocols, and resilient operations.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The package aligns this technical guidance with applicable NIST SP 800-53 requirements and DoD Comply-to-Connect objectives.\u00a0Each rule includes a requirement,\u00a0vulnerability\u00a0discussion, check procedure, remediation guidance, severity category, and Control Correlation Identifier. That structure can help assessment teams move from policy intent to evidence-based validation.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">What the STIG emphasizes for network access control<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">The NAC benchmark reflects a core Zero Trust principle: access should be based on verified identity, device context, and policy compliance rather than network location alone.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Its requirements address capabilities such as:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Protecting communications between endpoint agents and Cisco ISE with approved TLS settings<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Profiling endpoints that connect to the network<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Applying authorization policies based on device, identity, certificate, resource, or mission attributes<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Authenticating endpoints before trusted access is granted<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Assessing required endpoint security controls, including firewall, anti-malware, and host-based intrusion prevention capabilities when defined in the site\u2019s System Security Plan<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Denying, restricting, quarantining, or redirecting endpoints that fail required posture checks<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Applying restricted access to devices admitted through MAC Authentication Bypass<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Generating records and alerts for authentication failures, posture failures, audit-processing failures, and loss of communication with central logging services<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Continuously detecting and tracking attached endpoint devices<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">These are not abstract outcomes. Cisco ISE brings together identity, endpoint profiling, posture assessment, and policy-based authorization to help organizations\u00a0determine\u00a0who and what is connecting and what access should be allowed. Depending on policy, a device can be granted\u00a0appropriate access, assigned restricted access, redirected for remediation, quarantined, or denied.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This is where compliance and security architecture reinforce each other. The same controls that help an organization satisfy an assessment requirement can also reduce operational risk by limiting unverified access and making authorization decisions more consistent.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Protecting the policy decision point<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">The NDM benchmark addresses the other half of the equation: hardening and operating Cisco ISE as a security-critical platform.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Its requirements span areas including:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Administrative session controls and role-based privileges<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">External authentication for administrators and tightly controlled local accounts of last resort<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Account lockout, password policy, and required DoD notice and consent banners<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Audit generation for privileged activity and administrative events<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Centralized and redundant logging, including alerts for logging or monitoring failures<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Time synchronization using redundant authoritative sources<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">DoD-approved public key infrastructure and approved cryptographic mechanisms<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">FIPS-related configuration requirements<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Secure SNMP and remote maintenance communications<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Configuration and operational backups<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Removal or disabling of unnecessary services, ports, protocols, and functions<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Use of a Cisco-supported software release<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Verification of downloaded software integrity<\/span><span><br \/><\/span><\/li>\n<li><span data-contrast=\"auto\">Administrative session termination after the defined period of inactivity<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">The result is a defense-in-depth approach. Cisco ISE is assessed not only for the access control outcome it produces, but also for the integrity, confidentiality, accountability, and availability of the platform performing that work.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">What changed in Version 2, Release 4<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Version 2, Release 4 is a maintenance update rather than the first Cisco ISE STIG release. According to the revision history in the package, the July 2026 update makes a targeted change to the NAC check and fix guidance for posture settings in Cisco ISE versions after 3.1. It also updates NDM rule numbering and removes two requirements that no longer reflect how Cisco ISE\u00a0operates: one related to NTP configuration in the NDM guide and another related to cached administrator credentials and local accounts.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">These revisions illustrate why teams should treat STIG compliance as a lifecycle activity. Product capabilities, user interfaces, control interpretations, and supporting requirements evolve. Assessments and implementation records should therefore\u00a0identify\u00a0the exact STIG version and release used, rather than referring generically to \u201cthe Cisco ISE STIG.\u201d<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">A practical way to put the guidance to work<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"none\">Organizations can use the updated guide as the foundation for a repeatable implementation and evidence process:<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<ol>\n<li><b><span data-contrast=\"none\">Establish the Baseline: <\/span><\/b><span data-contrast=\"none\">Download the latest benchmark package from the DoD Cyber Exchange. Record the version, release number, and benchmark date, and preserve the original source package with your assessment evidence.<\/span><span><br \/><\/span><\/li>\n<li><b><span data-contrast=\"none\"> Define the Scope: <\/span><\/b><span data-contrast=\"none\">Identify all Cisco ISE nodes, personas, deployment roles, integrations, and target endpoint populations. Note that standalone services (such as Certificate Authority, Guest Portals, Provisioning Portal, and core AAA services) fall outside these two benchmarks\u2014evaluate what additional SRGs or STIGs apply when deploying those capabilities.<\/span><span><br \/><\/span><\/li>\n<li><b><span data-contrast=\"none\"> Align Benchmarks &amp; Teams: <\/span><\/b><span data-contrast=\"none\">Review both the Network Access Control (NAC) and Network Device Management (NDM) companion benchmarks. Assign individual checks to the appropriate owners across Network, Identity, Logging, System Admin, and Security Assessment teams.<\/span><span><br \/><\/span><\/li>\n<li><b><span data-contrast=\"none\"> Document Site-Specific Policies: <\/span><\/b><span data-contrast=\"none\">Capture organization-defined values, exceptions, endpoint populations, posture controls, logging\/syslog destinations, and mission requirements in the System Security Plan (SSP) and related artifacts.<\/span><span> <\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:264,&quot;469777462&quot;:[560,1120,1680,2240,2800,3360,3920,4480,5040,5600,6160,6720],&quot;469777927&quot;:[0,0,0,0,0,0,0,0,0,0,0,0],&quot;469777928&quot;:[1,1,1,1,1,1,1,1,1,1,1,1]}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"none\">Validatein Staging First: <\/span><\/b><span data-contrast=\"none\">Test all configuration changes in a representative staging\/lab environment. Settings should be thoroughly evaluated prior to production rollout because local architectures and operational dependencies vary.<\/span><span><br \/><\/span><\/li>\n<li><b><span data-contrast=\"none\"> Collect Durable Evidence: <\/span><\/b><span data-contrast=\"none\">Archive configuration exports, screenshots, policy records, log samples, test results, and formal approvals. A compliant configuration without repeatable, durable evidence can still result in assessment findings.<\/span><span><br \/><\/span><\/li>\n<li><b><span data-contrast=\"none\"> Plan for Continuous Compliance: <\/span><\/b><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:264,&quot;469777462&quot;:[560,1120,1680,2240,2800,3360,3920,4480,5040,5600,6160,6720],&quot;469777927&quot;:[0,0,0,0,0,0,0,0,0,0,0,0],&quot;469777928&quot;:[1,1,1,1,1,1,1,1,1,1,1,1]}\"\/><span data-contrast=\"none\">Reassess your deployment following Cisco ISE upgrades, policy modifications, integration updates, and new STIG releases. Ongoing monitoring prevents configuration drift from compromising your security posture over time<\/span><span><br \/><\/span><\/li>\n<\/ol>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">What the STIG does \u2013 and does not \u2013 mean<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">A product-specific STIG gives DoD organizations authoritative configuration and assessment guidance for using that product. It does not, by itself, constitute product approval, certify an entire deployment, or make a system fully secure. Product use and risk acceptance remain the responsibility of the\u00a0appropriate authorizing\u00a0official through the Risk Management Framework.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">That clarification does not diminish the importance of the guide. It makes its value more concrete. The Cisco ISE STIG gives security and network teams a common, testable language for discussing secure configuration, documenting risk, and\u00a0demonstrating\u00a0how policy is enforced at the point of network access.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">From compliance requirement to operational advantage<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Cisco ISE helps organizations translate identity, device posture, and mission context into network access decisions. The updated DISA guidance helps DoD teams configure and assess that capability with greater consistency.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">For federal security leaders, the opportunity is to use the STIG as more than a point-in-time checklist. When its requirements are integrated into architecture reviews, change management, automated configuration workflows, evidence collection, and continuous monitoring, the guide can support both audit readiness and stronger day-to-day cyber defense.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The destination is not simply a\u00a0completed\u00a0checklist. It is a network where trust is continually evaluated, access is deliberately controlled, and security decisions can be explained with evidence.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2><b><span data-contrast=\"auto\">Calls to Action<\/span><\/b><\/h2>\n<\/div>\n<p><p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>co-authored by Jim Kotantoulas, DoD Cisco Security Engineer\u00a0 For U.S. Department of\u00a0Defense\u00a0organizations, security policy only creates value when it can be translated into consistent technical [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":17344,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-17343","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/17343","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/comments?post=17343"}],"version-history":[{"count":0,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/17343\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media\/17344"}],"wp:attachment":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media?parent=17343"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/categories?post=17343"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/tags?post=17343"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}