STIGQter STIGQter: STIG Summary: Cisco ACI NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

The Cisco ACI must be configured to synchronize system clocks within and between systems or system components.

DISA Rule

SV-271971r1168430_rule

Vulnerability Number

V-271971

Group Title

SRG-APP-000920-NDM-000320

Rule Version

CACI-ND-000056

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Create an NTP policy:
1. Navigate to Fabric >> Quickstart and click "Create an NTP Policy Link".
2. Complete the form.
- Provide a name for the policy.
- Set the State to "Enabled".
3. Click "Next" to define the NTP Sources.
4. Define at least two DOD-approved time servers. Leave all the default options and click "OK". Refer to note below.
5. Navigate to Fabric >> Fabric Policies submenu >> Pods >> Policy Groups folder to add the NTP Policy to the appropriate Fabric Pod Policy or group to assign to one or more Pods in the fabric.
6. Right-click the Policy Groups folder. Select an existing Pod Policy Group or create a new group.
7. Select the policy for NTP created in the previous step.
8. Navigate to Fabric >> Fabric Policies submenu >> Pods >> Profiles >> Pod Profile >> default. If needed, with the default Pod Selector selected in the navigation pane, change the Fabric Policy Group to the one created in the previous step.

Note: DOD-approved solutions consist of a combination of a primary and secondary time source using a combination or multiple instances of the following: a time server designated for the appropriate DOD network (NIPRNet/SIPRNet), USNO time servers, and/or GPS. The secondary time source must be located in a different geographic region than the primary time source.

Check Contents

1. Navigate to Fabric >> Fabric Policies.
2. Expand "Policies".
3. Expand "Pod".
4. Expand "Date and Time".
5. Expand each "Date and Time Policy".
6. Verify at least two DOD-approved time sources are configured.

Note: DOD-approved solutions consist of a combination of a primary and secondary time source using a combination or multiple instances of the following: a time server designated for the appropriate DOD network (NIPRNet/SIPRNet); United States Naval Observatory (USNO) time servers; and/or the Global Positioning System (GPS). The secondary time source must be located in a different geographic region than the primary time source.

If Cisco ACI fabric does not use DOD-approved redundant NTP sources that use authentication that is cryptographically based, this is a finding.

Vulnerability Number

V-271971

Documentable

False

Rule Version

CACI-ND-000056

Severity Override Guidance

1. Navigate to Fabric >> Fabric Policies.
2. Expand "Policies".
3. Expand "Pod".
4. Expand "Date and Time".
5. Expand each "Date and Time Policy".
6. Verify at least two DOD-approved time sources are configured.

Note: DOD-approved solutions consist of a combination of a primary and secondary time source using a combination or multiple instances of the following: a time server designated for the appropriate DOD network (NIPRNet/SIPRNet); United States Naval Observatory (USNO) time servers; and/or the Global Positioning System (GPS). The secondary time source must be located in a different geographic region than the primary time source.

If Cisco ACI fabric does not use DOD-approved redundant NTP sources that use authentication that is cryptographically based, this is a finding.

Check Content Reference

M

Target Key

5682