STIGQter STIGQter: STIG Summary:

Cisco ACI NDM Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 05 Jan 2026

CheckedNameTitle
SV-271916r1168349_ruleThe Cisco ACI must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC).
SV-271917r1114333_ruleThe Cisco ACI must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).
SV-271918r1168426_ruleThe Cisco ACI must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the device.
SV-271919r1168355_ruleThe Cisco ACI must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes.
SV-271920r1168358_ruleThe Cisco ACI must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.
SV-271921r1113817_ruleThe Cisco ACI must conduct backups of the configuration weekly or at an organization-defined frequency and store on a separate device.
SV-271922r1168360_ruleThe Cisco ACI must obtain its public key certificates from an appropriate certificate policy through an approved service provider.
SV-271923r1114182_ruleThe Cisco ACI must use DOD-approved Network Time Protocol (NTP) sources that use authentication that is cryptographically based.
SV-271924r1168362_ruleThe Cisco APIC must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.
SV-271926r1168364_ruleThe Cisco ACI must be running an operating system release that is currently supported by the vendor.
SV-271927r1168428_ruleThe Cisco ACI must be configured to assign appropriate user roles or access levels to authenticated users.
SV-271929r1113827_ruleThe Cisco ACI must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
SV-271931r1168368_ruleThe Cisco ACI must be configured to send log data to a central log server for log retention and forwarding alerts to the administrators and the information system security officer (ISSO).
SV-271932r1114348_ruleThe Cisco ACI must be configured to alert organization-defined personnel or roles upon detection of unauthorized access, modification, or deletion of audit information.
SV-271933r1114169_ruleThe Cisco ACI must audit the enforcement actions used to restrict access associated with changes to the device.
SV-271935r1114172_ruleThe Cisco ACI must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-271936r1113837_ruleThe Cisco ACI must implement replay-resistant authentication mechanisms for network access to privileged accounts.
SV-271939r1114173_ruleThe Cisco ACI must automatically audit account creation.
SV-271944r1168370_ruleThe Cisco ACI must generate log records for a locally developed list of auditable events.
SV-271958r1168373_ruleThe Cisco ACI must be configured to allow user selection of long passwords and passphrases, including spaces and all printable characters, for password-based authentication.
SV-271960r1168376_ruleThe Cisco ACI must enforce a minimum 15-character password length.
SV-271966r1114341_ruleThe Cisco ACI must use FIPS 140-2/140-3 approved algorithms for authentication to a cryptographic module.
SV-271969r1168379_ruleCisco ACI SSH sessions must be terminated after five minutes of inactivity.
SV-271971r1168430_ruleThe Cisco ACI must be configured to synchronize system clocks within and between systems or system components.
SV-271972r1114185_ruleThe Cisco ACI must be configured to disable the auxiliary USB port.
SV-271975r1168383_ruleThe Cisco ACI must limit the number of concurrent sessions to one for each administrator account.