STIGQter STIGQter: STIG Summary: Cisco ISE NAC Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The Cisco ISE must use TLS 1.2, at a minimum, to protect the confidentiality of information passed between the endpoint agent and the Cisco ISE. This is This is required for compliance with C2C Step 1.

DISA Rule

SV-242575r812732_rule

Vulnerability Number

V-242575

Group Title

SRG-NET-000062-NAC-000340

Rule Version

CSCO-NC-000010

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure ISE so that only TLS 1.2 is enabled:

From the Web Admin portal:
1. Navigate to Administration >> System >> Settings >> Security Settings.
2. Ensure "Allow TLS1.0", "Allow TLS1.1", and "Allow legacy unsafe TLS renegotiation for ISE as a client" are unchecked.

Check Contents

If DoD is not at C2C Step 1 or higher, this is not a finding.

Verify that only TLS 1.2 is enabled.

From the Web Admin portal:
1. Navigate to Administration >> System >> Settings >> Security Settings.
2. Ensure "Allow TLS1.0", "Allow TLS1.1", and "Allow legacy unsafe TLS renegotiation for ISE as a client" are unchecked.

If TLS 1.0 or 1.1 is enabled, this is a finding.

Vulnerability Number

V-242575

Documentable

False

Rule Version

CSCO-NC-000010

Severity Override Guidance

If DoD is not at C2C Step 1 or higher, this is not a finding.

Verify that only TLS 1.2 is enabled.

From the Web Admin portal:
1. Navigate to Administration >> System >> Settings >> Security Settings.
2. Ensure "Allow TLS1.0", "Allow TLS1.1", and "Allow legacy unsafe TLS renegotiation for ISE as a client" are unchecked.

If TLS 1.0 or 1.1 is enabled, this is a finding.

Check Content Reference

M

Target Key

5383