STIGQter STIGQter: STIG Summary: Cisco ASA NDM Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Cisco ASA must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.

DISA Rule

SV-239924r1015262_rule

Vulnerability Number

V-239924

Group Title

SRG-APP-000373-NDM-000298

Rule Version

CASA-ND-000940

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Cisco ASA to synchronize its clock with redundant authoritative time sources as shown in the example below.

ASA(config)# ntp server 10.1.48.8 prefer
ASA(config)# ntp server 10.1.22.2
ASA(config)# end

Check Contents

Review the Cisco ASA configuration to verify it is compliant with this requirement as shown in the configuration example below.

ntp server 10.1.22.2
ntp server 10.1.48.8 prefer

Note: For ASAs running on Firepower Chassis hardware, the NTP settings are visible in the FXOS web UI only (not in the ASA CLI or ASDM web UI).

If the Cisco ASA is not configured to synchronize its clock with redundant authoritative time sources, this is a finding.

Vulnerability Number

V-239924

Documentable

False

Rule Version

CASA-ND-000940

Severity Override Guidance

Review the Cisco ASA configuration to verify it is compliant with this requirement as shown in the configuration example below.

ntp server 10.1.22.2
ntp server 10.1.48.8 prefer

Note: For ASAs running on Firepower Chassis hardware, the NTP settings are visible in the FXOS web UI only (not in the ASA CLI or ASDM web UI).

If the Cisco ASA is not configured to synchronize its clock with redundant authoritative time sources, this is a finding.

Check Content Reference

M

Target Key

5342