STIGQter STIGQter: STIG Summary: Cisco ASA NDM Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Cisco ASA must be configured to terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements.

DISA Rule

SV-239920r961068_rule

Vulnerability Number

V-239920

Group Title

SRG-APP-000190-NDM-000267

Rule Version

CASA-ND-000690

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Set the idle timeout value to five minutes or less for console, ssh, and http (if ASDM is used) access.

SW1(config)# ssh timeout 5
SW1(config)# console timeout 5
ASA(config)# http server idle-timeout 5
SW1(config)# end

Check Contents

Review the Cisco ASA configuration to verify all network connections associated with a device management have an idle timeout value set to five minutes or less as shown in the following example:

http server idle-timeout 5



ssh timeout 5



console timeout 5

If the Cisco ASA is not configured to terminate all network connections associated with a device management after five minutes of inactivity, this is a finding.

Vulnerability Number

V-239920

Documentable

False

Rule Version

CASA-ND-000690

Severity Override Guidance

Review the Cisco ASA configuration to verify all network connections associated with a device management have an idle timeout value set to five minutes or less as shown in the following example:

http server idle-timeout 5



ssh timeout 5



console timeout 5

If the Cisco ASA is not configured to terminate all network connections associated with a device management after five minutes of inactivity, this is a finding.

Check Content Reference

M

Target Key

5342