STIGQter STIGQter: STIG Summary:

Cisco ASA NDM Security Technical Implementation Guide

Version: 2

Release: 5 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-239896r960735_ruleThe Cisco ASA must be configured to limit the number of concurrent management sessions to an organization-defined number.
SV-239897r960777_ruleThe Cisco ASA must be configured to automatically audit account creation.
SV-239898r960780_ruleThe Cisco ASA must be configured to automatically audit account modification.
SV-239899r960783_ruleThe Cisco ASA must be configured to automatically audit account-disabling actions.
SV-239900r960786_ruleThe Cisco ASA must be configured to automatically audit account removal actions.
SV-239901r1137875_ruleThe Cisco ASA must be configured to enforce approved authorizations for controlling the flow of management information within the Cisco ASA based on information flow control policies.
SV-239902r960843_ruleThe Cisco ASA must be configured to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.
SV-239903r960864_ruleThe Cisco ASA must be configured to protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
SV-239904r960885_ruleThe Cisco ASA must be configured to generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-239905r960891_ruleThe Cisco ASA must be configured to produce audit log records containing sufficient information to establish what type of event occurred.
SV-239906r960894_ruleThe Cisco ASA must be configured to produce audit records containing information to establish when (date and time) the events occurred.
SV-239907r960897_ruleThe Cisco ASA must be configured to produce audit records containing information to establish where the events occurred.
SV-239908r960900_ruleThe Cisco ASA must be configured to produce audit log records containing information to establish the source of events.
SV-239909r960903_ruleThe Cisco ASA must be configured to produce audit records that contain information to establish the outcome of the event.
SV-239910r960909_ruleThe Cisco ASA must be configured to generate audit records containing the full-text recording of privileged commands.
SV-239911r1043177_ruleThe Cisco ASA must be configured to prohibit the use of all unnecessary and/or non-secure functions, ports, protocols, and/or services.
SV-239912r1051115_ruleThe Cisco ASA must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
SV-239913r960993_ruleThe Cisco ASA must be configured to implement replay-resistant authentication mechanisms for network access to privileged accounts.
SV-239914r1015256_ruleThe Cisco ASA must be configured to enforce a minimum 15-character password length.
SV-239915r1015257_ruleThe Cisco ASA must be configured to enforce password complexity by requiring that at least one uppercase character be used.
SV-239916r1015258_ruleThe Cisco ASA must be configured to enforce password complexity by requiring that at least one lowercase character be used.
SV-239917r1015259_ruleThe Cisco ASA must be configured to enforce password complexity by requiring that at least one numeric character be used.
SV-239918r1015260_ruleThe Cisco ASA must be configured to enforce password complexity by requiring that at least one special character be used.
SV-239919r1043189_ruleThe Cisco ASA must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password.
SV-239920r961068_ruleThe Cisco ASA must be configured to terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements.
SV-239921r961362_ruleThe Cisco ASA must be configured to audit the execution of privileged functions.
SV-239922r961392_ruleThe Cisco ASA must be configured to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-239923r991812_ruleThe Cisco ASA must be configured to generate an immediate real-time alert of all audit failure events requiring real-time alerts.
SV-239924r1015262_ruleThe Cisco ASA must be configured to synchronize its clock with the primary and secondary time sources using redundant authoritative time sources.
SV-239925r961446_ruleThe Cisco ASA must be configured to record time stamps for audit records that meet a granularity of one second for a minimum degree of precision.
SV-239927r961506_ruleThe Cisco ASA must be configured to authenticate Simple Network Management Protocol (SNMP) messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).
SV-239928r961506_ruleThe Cisco ASA must be configured to encrypt Simple Network Management Protocol (SNMP) messages using a FIPS 140-2 approved algorithm.
SV-239929r1167249_ruleThe Cisco ASA must be configured to authenticate Network Time Protocol (NTP) sources using authentication with FIPS-compliant algorithms.
SV-239930r961554_ruleThe Cisco ASA must be configured to use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of non-local maintenance and diagnostic communications.
SV-239931r961557_ruleThe Cisco ASA must be configured to implement cryptographic mechanisms using a FIPS 140-2 approved algorithm to protect the confidentiality of remote maintenance sessions.
SV-239932r961620_ruleThe Cisco ASA must be configured to protect against known types of denial-of-service (DoS) attacks by enabling the Threat Detection feature.
SV-239933r961800_ruleThe Cisco ASA must be configured to generate audit records when successful/unsuccessful attempts to modify administrator privileges occur.
SV-239934r961812_ruleThe Cisco ASA must be configured to generate audit records when successful/unsuccessful attempts to delete administrator privileges occur.
SV-239935r961824_ruleThe Cisco ASA must be configured to generate audit records when successful/unsuccessful logon attempts occur.
SV-239936r961827_ruleThe Cisco ASA must be configured to generate audit records for privileged activities or other system-level access.
SV-239937r961830_ruleThe Cisco ASA must be configured to generate audit records showing starting and ending time for administrator access to the system.
SV-239938r961833_ruleThe Cisco ASA must be configured to generate audit records when concurrent logons from different workstations occur.
SV-239940r1137887_ruleThe Cisco ASA must be configured to use at least two authentication servers to authenticate users prior to granting administrative access.
SV-239941r1205824_ruleThe Cisco ASA must be configured to conduct backups of system-level information contained in the information system when changes occur.
SV-239942r991816_ruleThe Cisco ASA must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider.
SV-239943r1137890_ruleThe Cisco ASA must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to organization-defined personnel and/or the firewall administrator.
SV-239944r961863_ruleThe Cisco ASA must be running an operating system release that is currently supported by Cisco Systems.