STIGQter STIGQter: STIG Summary: Cisco ISE NDM Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

The Cisco ISE must be configured to synchronize internal information system clocks using redundant authoritative time sources.

DISA Rule

SV-242629r1168433_rule

Vulnerability Number

V-242629

Group Title

SRG-APP-000373-NDM-000298

Rule Version

CSCO-NM-000230

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Choose Administration >> System >> Settings >> System Time.
2. Enter unique IP addresses (IPv4/IPv6/FQDN) for the NTP servers.
3. Configure redundant NTP server addresses.


Note: If authentication settings are no longer available, then a DOD-approved solution must be used. Use of MD5 results in a CAT 2 (CSCO-NM-000390) finding since NTP authentication is required. DOD-approved solutions consist of a combination of a primary and secondary time source using a combination or multiple instances of the following: a time server designated for the appropriate DOD network (NIPRNet/SIPRNet); United States Naval Observatory (USNO) time servers; and/or the Global Positioning System (GPS). The secondary time source must be located in a different geographic region than the primary time source.

Check Contents

1. View the status of the Network Translation Protocol (NTP) associations.

show ntp

2. Verify a primary and secondary ntp server address is configured.

If the Cisco ISE is not configured to synchronize internal information system clocks using redundant authoritative time sources, this is a finding.

Vulnerability Number

V-242629

Documentable

False

Rule Version

CSCO-NM-000230

Severity Override Guidance

1. View the status of the Network Translation Protocol (NTP) associations.

show ntp

2. Verify a primary and secondary ntp server address is configured.

If the Cisco ISE is not configured to synchronize internal information system clocks using redundant authoritative time sources, this is a finding.

Check Content Reference

M

Target Key

5384