STIGQter STIGQter: STIG Summary: Cisco ISE NAC Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 13 Apr 2021:

The Cisco ISE must generate a log record when the client machine fails posture assessment because required security software is missing or has been deleted.

DISA Rule

SV-242590r714080_rule

Vulnerability Number

V-242590

Group Title

SRG-NET-000492-NAC-002101

Rule Version

CSCO-NC-000160

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure a log to be generated and sent when an Endpoint has a change in posture status.

From the Web Admin portal:
1. Choose Administration >> System >> Logging >> Logging Categories.
2. Configure the "Posture and Client Provisioning Audit" category and the Targets field to have LogCollector selected at a minimum. (This is the default setting.) If the environment has an additional SYSLOG server, it can be selected here as well.

Check Contents

Verify that a log will be generated and sent when an Endpoint has a change in posture status.

From the Web Admin portal:
1. Choose Administration >> System >> Logging >> Logging Categories.
2. Verify the Posture and Client Provisioning Audit has LogCollector set as a target at a minimum.

If the Posture and Client Provisioning Audit logging category is not configured to send to the LogCollector and/or another logging target, this is a finding.

Vulnerability Number

V-242590

Documentable

False

Rule Version

CSCO-NC-000160

Severity Override Guidance

Verify that a log will be generated and sent when an Endpoint has a change in posture status.

From the Web Admin portal:
1. Choose Administration >> System >> Logging >> Logging Categories.
2. Verify the Posture and Client Provisioning Audit has LogCollector set as a target at a minimum.

If the Posture and Client Provisioning Audit logging category is not configured to send to the LogCollector and/or another logging target, this is a finding.

Check Content Reference

M

Target Key

5383

Comments