DoD Updates STIG for Cisco ISE, Emphasizing Zero Trust Principles
The U.S. Department of Defense (DoD) has updated its Security Technical Implementation Guide for Cisco Identity Services Engine (ISE). The new guide, published by the Defense Information Systems Agency (DISA), provides a repeatable baseline for reviewing how Cisco ISE is configured to protect its own management plane and perform its network access control mission.
The guide connects security policy to practical controls for identifying endpoints, evaluating posture, making authorization decisions, restricting non-compliant devices, and producing audit evidence needed to support ongoing risk management. It consists of two complementary benchmarks: the Cisco ISE Network Access Control (NAC) STIG and the Cisco ISE Network Device Management (NDM) STIG.
The NAC benchmark reflects a core Zero Trust principle: access should be based on verified identity, device context, and policy compliance rather than network location alone. It addresses capabilities such as protecting communications between endpoint agents and Cisco ISE with approved TLS settings, profiling endpoints that connect to the network, and applying authorization policies based on device, identity, certificate, resource, or mission attributes.
The NDM benchmark focuses on hardening and operating Cisco ISE as a security-critical platform. Its requirements span areas including administrative session controls and role-based privileges, external authentication for administrators, audit generation for privileged activity, centralized and redundant logging, time synchronization using redundant authoritative sources, and DoD-approved public key infrastructure.