Cisco and the DISA STIG: Turning Zero Trust Policy into Repeatable Practice – Part 1: Cisco ISE

co-authored by Jim Kotantoulas, DoD Cisco Security Engineer 

For U.S. Department of Defense organizations, security policy only creates value when it can be translated into consistent technical practice. That is why Security Technical Implementation Guides, or STIGs, matter: they turn cybersecurity requirements into configuration and assessment criteria that administrators, assessors, and authorizing officials can apply in operational environments. 

The Defense Information Systems Agency (DISA) has published an updated Security Technical Implementation Guide for Cisco Identity Services Engine. The Cisco ISE STIG Version 2, Release 4, dated July 1, 2026, was developed by Cisco Systems and DISA for the Department of Defense. It gives DoD teams a repeatable baseline for reviewing how Cisco ISE is configured to protect its own management plane and perform its network access control mission. 

For organizations already using Cisco ISE as a policy decision point, the guide provides more than a compliance checklist. It connects security policy to practical controls for identifying endpoints, evaluating posture, making authorization decisions, restricting noncompliant devices, and producing the audit evidence needed to support ongoing risk management. 

One package, two essential security perspectives 

The Cisco ISE STIG package contains two complementary benchmarks: 

  • Cisco ISE Network Access Control (NAC) STIG: Focuses on the policies and services Cisco ISE uses to evaluate endpoints and control access to the network. The Version 2, Release 4 benchmark contains 30 requirements.
  • Cisco ISE Network Device Management (NDM) STIG: Focuses on securely administering and operating the Cisco ISE platform itself. The Version 2, Release 4 benchmark contains 51 requirements. 

Together, the two benchmarks contain 81 checks. The STIG overview states that both the NAC and NDM guides are required for a Cisco ISE security review. That distinction is important. An organization cannot evaluate only the access decisions made by Cisco ISE while overlooking the security of the system making those decisions. Strong policy enforcement depends on a well-protected management plane, trusted administrative access, reliable time and logging, supported software, secure protocols, and resilient operations. 

The package aligns this technical guidance with applicable NIST SP 800-53 requirements and DoD Comply-to-Connect objectives. Each rule includes a requirement, vulnerability discussion, check procedure, remediation guidance, severity category, and Control Correlation Identifier. That structure can help assessment teams move from policy intent to evidence-based validation. 

What the STIG emphasizes for network access control 

The NAC benchmark reflects a core Zero Trust principle: access should be based on verified identity, device context, and policy compliance rather than network location alone. 

Its requirements address capabilities such as: 

  • Protecting communications between endpoint agents and Cisco ISE with approved TLS settings
  • Profiling endpoints that connect to the network
  • Applying authorization policies based on device, identity, certificate, resource, or mission attributes
  • Authenticating endpoints before trusted access is granted
  • Assessing required endpoint security controls, including firewall, anti-malware, and host-based intrusion prevention capabilities when defined in the site’s System Security Plan
  • Denying, restricting, quarantining, or redirecting endpoints that fail required posture checks
  • Applying restricted access to devices admitted through MAC Authentication Bypass
  • Generating records and alerts for authentication failures, posture failures, audit-processing failures, and loss of communication with central logging services
  • Continuously detecting and tracking attached endpoint devices 

These are not abstract outcomes. Cisco ISE brings together identity, endpoint profiling, posture assessment, and policy-based authorization to help organizations determine who and what is connecting and what access should be allowed. Depending on policy, a device can be granted appropriate access, assigned restricted access, redirected for remediation, quarantined, or denied. 

This is where compliance and security architecture reinforce each other. The same controls that help an organization satisfy an assessment requirement can also reduce operational risk by limiting unverified access and making authorization decisions more consistent. 

Protecting the policy decision point 

The NDM benchmark addresses the other half of the equation: hardening and operating Cisco ISE as a security-critical platform. 

Its requirements span areas including: 

  • Administrative session controls and role-based privileges
  • External authentication for administrators and tightly controlled local accounts of last resort
  • Account lockout, password policy, and required DoD notice and consent banners
  • Audit generation for privileged activity and administrative events
  • Centralized and redundant logging, including alerts for logging or monitoring failures
  • Time synchronization using redundant authoritative sources
  • DoD-approved public key infrastructure and approved cryptographic mechanisms
  • FIPS-related configuration requirements
  • Secure SNMP and remote maintenance communications
  • Configuration and operational backups
  • Removal or disabling of unnecessary services, ports, protocols, and functions
  • Use of a Cisco-supported software release
  • Verification of downloaded software integrity
  • Administrative session termination after the defined period of inactivity 

The result is a defense-in-depth approach. Cisco ISE is assessed not only for the access control outcome it produces, but also for the integrity, confidentiality, accountability, and availability of the platform performing that work. 

What changed in Version 2, Release 4 

Version 2, Release 4 is a maintenance update rather than the first Cisco ISE STIG release. According to the revision history in the package, the July 2026 update makes a targeted change to the NAC check and fix guidance for posture settings in Cisco ISE versions after 3.1. It also updates NDM rule numbering and removes two requirements that no longer reflect how Cisco ISE operates: one related to NTP configuration in the NDM guide and another related to cached administrator credentials and local accounts. 

These revisions illustrate why teams should treat STIG compliance as a lifecycle activity. Product capabilities, user interfaces, control interpretations, and supporting requirements evolve. Assessments and implementation records should therefore identify the exact STIG version and release used, rather than referring generically to “the Cisco ISE STIG.” 

A practical way to put the guidance to work 

Organizations can use the updated guide as the foundation for a repeatable implementation and evidence process: 

  1. Establish the Baseline: Download the latest benchmark package from the DoD Cyber Exchange. Record the version, release number, and benchmark date, and preserve the original source package with your assessment evidence.
  2. Define the Scope: Identify all Cisco ISE nodes, personas, deployment roles, integrations, and target endpoint populations. Note that standalone services (such as Certificate Authority, Guest Portals, Provisioning Portal, and core AAA services) fall outside these two benchmarks—evaluate what additional SRGs or STIGs apply when deploying those capabilities.
  3. Align Benchmarks & Teams: Review both the Network Access Control (NAC) and Network Device Management (NDM) companion benchmarks. Assign individual checks to the appropriate owners across Network, Identity, Logging, System Admin, and Security Assessment teams.
  4. Document Site-Specific Policies: Capture organization-defined values, exceptions, endpoint populations, posture controls, logging/syslog destinations, and mission requirements in the System Security Plan (SSP) and related artifacts.  
  5. Validatein Staging First: Test all configuration changes in a representative staging/lab environment. Settings should be thoroughly evaluated prior to production rollout because local architectures and operational dependencies vary.
  6. Collect Durable Evidence: Archive configuration exports, screenshots, policy records, log samples, test results, and formal approvals. A compliant configuration without repeatable, durable evidence can still result in assessment findings.
  7. Plan for Continuous Compliance: Reassess your deployment following Cisco ISE upgrades, policy modifications, integration updates, and new STIG releases. Ongoing monitoring prevents configuration drift from compromising your security posture over time

What the STIG does – and does not – mean 

A product-specific STIG gives DoD organizations authoritative configuration and assessment guidance for using that product. It does not, by itself, constitute product approval, certify an entire deployment, or make a system fully secure. Product use and risk acceptance remain the responsibility of the appropriate authorizing official through the Risk Management Framework. 

That clarification does not diminish the importance of the guide. It makes its value more concrete. The Cisco ISE STIG gives security and network teams a common, testable language for discussing secure configuration, documenting risk, and demonstrating how policy is enforced at the point of network access. 

From compliance requirement to operational advantage 

Cisco ISE helps organizations translate identity, device posture, and mission context into network access decisions. The updated DISA guidance helps DoD teams configure and assess that capability with greater consistency. 

For federal security leaders, the opportunity is to use the STIG as more than a point-in-time checklist. When its requirements are integrated into architecture reviews, change management, automated configuration workflows, evidence collection, and continuous monitoring, the guide can support both audit readiness and stronger day-to-day cyber defense. 

The destination is not simply a completed checklist. It is a network where trust is continually evaluated, access is deliberately controlled, and security decisions can be explained with evidence. 

Calls to Action

Discover Cisco for Industries

Discover Cisco for Industries

Learn how Cisco is connecting and protecting industries in the AI era. Review our industries

Discover more
Explore our industry use cases

Explore our industry use cases

Utilize Cisco’s Use Case Explorer to discover the use cases that are making a difference in your industry. Start exploring

Learn more

Leave a Comment

x
1
1
Voices are browser-dependent.
Tip: Chrome provides the most options.