SV-242654r961554_rule
V-242654
SRG-APP-000411-NDM-000330
CSCO-NM-000490
CAT II
10
Enable FIPS Mode in Cisco ISE to ensure FIPS 140-2/3 algorithms are used in all security functions requiring cryptographic functions.
1. Choose Administration >> System >> Settings >> FIPS Mode.
2. Choose the "Enabled" option from the FIPS Mode drop-down list.
3. Click "Save" and restart the node.
NOTE: Configuring FIPS mode is the required DoD configuration. However, this requirement can be lowered to a CAT 3 if the alternative manual configuration is used to configure a FIPS 140-2/3 validated HMAC to protect the integrity of nonlocal maintenance and diagnostic communications.
Navigate to Administration >> System >> Settings >> FIPS Mode.
Verify FIPS Mode is enabled.
If FIPS Mode is enabled, this is not a finding.
If FIPS mode is not configured, but the Cisco ISE is configured using an alternative manual method to configure to configure a FIPS 140-2/3 validated HMAC to protect the integrity of nonlocal maintenance and diagnostic communication, this can be lowered to a CAT 3 finding.
V-242654
False
CSCO-NM-000490
Navigate to Administration >> System >> Settings >> FIPS Mode.
Verify FIPS Mode is enabled.
If FIPS Mode is enabled, this is not a finding.
If FIPS mode is not configured, but the Cisco ISE is configured using an alternative manual method to configure to configure a FIPS 140-2/3 validated HMAC to protect the integrity of nonlocal maintenance and diagnostic communication, this can be lowered to a CAT 3 finding.
M
5384