UCF STIG Viewer Logo

The Cisco ISE must off-load log records onto a different system. This is required for compliance with C2C Step 1.


Overview

Finding ID Version Rule ID IA Controls Severity
V-242593 CSCO-NC-000190 SV-242593r812768_rule Medium
Description
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity. This does not apply to audit logs generated on behalf of the device itself (management).
STIG Date
Cisco ISE NAC Security Technical Implementation Guide 2021-12-21

Details

Check Text ( C-45868r812767_chk )
If DoD is not at C2C Step 1 or higher, this is not a finding.

Navigate to Administration >> System >> Backup and Restore.

Ensure that operational data backups are scheduled.

If operational backups are not scheduled, this is a finding.
Fix Text (F-45825r714088_fix)
From the Web Admin portal:
1. Navigate to Administration >> System >> Backup and Restore.
2. Select the "Schedule" option next to Operational Data Backup.
3. Configure operational data backup at a desired frequency.