STIGQter STIGQter: STIG Summary: Cisco ASA NDM Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Cisco ASA must be configured to enforce approved authorizations for controlling the flow of management information within the Cisco ASA based on information flow control policies.

DISA Rule

SV-239901r1137875_rule

Vulnerability Number

V-239901

Group Title

SRG-APP-000038-NDM-000213

Rule Version

CASA-ND-000140

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Cisco ASA to restrict management access to specific IP addresses via SSH as shown in the example below.

ASA(config)# ssh x.x.x.0 255.255.255.0 INSIDE
ASA(config)# end

Check Contents

Review the Cisco ASA configuration to verify that management access is restricted to specific IP address space as shown in the example below.

ssh x.x.x.0 255.255.255.0 INSIDE

If the Cisco ASA is not configured to enforce approved authorizations for controlling the flow of management information within the device based on control policies, this is a finding.

Vulnerability Number

V-239901

Documentable

False

Rule Version

CASA-ND-000140

Severity Override Guidance

Review the Cisco ASA configuration to verify that management access is restricted to specific IP address space as shown in the example below.

ssh x.x.x.0 255.255.255.0 INSIDE

If the Cisco ASA is not configured to enforce approved authorizations for controlling the flow of management information within the device based on control policies, this is a finding.

Check Content Reference

M

Target Key

5342