STIGQter STIGQter: STIG Summary: Cisco ASA NDM Security Technical Implementation Guide Version: 2 Release: 5 Benchmark Date: 01 Jul 2026:

The Cisco ASA must be configured to protect against known types of denial-of-service (DoS) attacks by enabling the Threat Detection feature.

DISA Rule

SV-239932r961620_rule

Vulnerability Number

V-239932

Group Title

SRG-APP-000435-NDM-000315

Rule Version

CASA-ND-001180

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Cisco ASA to protect against known types of DoS attacks by enabling the Threat Detection feature.

ASA(config)# threat-detection basic-threat
ASA(config)# end

Check Contents

Note: When operating the ASA in multi-context mode with a separate IDPS, threat detection cannot be enabled, and this check is Not Applicable.

Review the ASA configuration and verify the Threat Detection feature is enabled as shown in the example below.

threat-detection basic-threat

If the Cisco ASA does not have the Threat Detection feature enabled, this is a finding.

Vulnerability Number

V-239932

Documentable

False

Rule Version

CASA-ND-001180

Severity Override Guidance

Note: When operating the ASA in multi-context mode with a separate IDPS, threat detection cannot be enabled, and this check is Not Applicable.

Review the ASA configuration and verify the Threat Detection feature is enabled as shown in the example below.

threat-detection basic-threat

If the Cisco ASA does not have the Threat Detection feature enabled, this is a finding.

Check Content Reference

M

Target Key

5342