Cisco and DISA Release STIG for Securely Configuring SNA
Cisco has partnered with the Defense Information Systems Agency (DISA) to release a product-specific Security Technical Implementation Guide (STIG) for securely configuring Cisco Secure Network Analytics (SNA). This guide, version 1, release 1, dated June 29, 2026, provides a common technical baseline for hardening an agentless network detection and response platform that may hold sensitive network telemetry, security findings, and investigative context.
The STIG has 31 requirements, with 8 rated as high severity and 23 rated as medium severity. Each requirement includes a vulnerability discussion, assessment procedure, remediation guidance, severity rating, and Control Correlation Identifier that connects the technical check to broader cybersecurity policy.
The guide is derived from NIST SP 800-53 and related requirements, supporting the evidence-based assessment process used within the Risk Management Framework. It gives system owners, engineers, and assessors a shared definition of the expected secure state.