STIGQter STIGQter: STIG Summary: Cisco ASA NDM Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Cisco ASA must be configured to audit the execution of privileged functions.

DISA Rule

SV-239921r961362_rule

Vulnerability Number

V-239921

Group Title

SRG-APP-000343-NDM-000289

Rule Version

CASA-ND-000910

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Cisco ASA to log all configuration changes as shown in the following example.

ASA(config)# logging enable
ASA(config)# logging buffered informational
ASA(config)# end

Check Contents

Review the Cisco ASA configuration to verify that it is compliant with this requirement. The configuration example below will log all configuration changes.

logging enable
logging buffered informational

Note: The ASA will log all EXEC-mode commands.

If the Cisco ASA is not configured to log all configuration changes, this is a finding.

Vulnerability Number

V-239921

Documentable

False

Rule Version

CASA-ND-000910

Severity Override Guidance

Review the Cisco ASA configuration to verify that it is compliant with this requirement. The configuration example below will log all configuration changes.

logging enable
logging buffered informational

Note: The ASA will log all EXEC-mode commands.

If the Cisco ASA is not configured to log all configuration changes, this is a finding.

Check Content Reference

M

Target Key

5342