UCF STIG Viewer Logo

The Cisco ISE must generate a critical alert to be sent to the ISSO and SA (at a minimum) in the event of an audit processing failure. This is required for compliance with C2C Step 1.


Overview

Finding ID Version Rule ID IA Controls Severity
V-242594 CSCO-NC-000200 SV-242594r812770_rule Medium
Description
It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without an alert, security personnel may be unaware of an impending failure of the audit capability and system operation may be adversely affected. Cisco ISE provides system alarms which notify the administrator when critical system condition occurs. Alarms are displayed in the Alarm dashlet. Administrators can configured the dashlet to receive notification of alarms through e-mail and/or syslog messages.
STIG Date
Cisco ISE NAC Security Technical Implementation Guide 2021-12-21

Details

Check Text ( C-45869r812769_chk )
If DoD is not at C2C Step 1 or higher, this is not a finding.

Verify the Cisco ISE will notify one or more individuals when there is a Log Collection Error.

From the Web Admin portal:
1. Choose Administration >> System >> Settings >> Alarm Settings.
2. Select "Log Collector Error" from the list of default alarms and click "Edit".
3. Verify that "Enable" is selected.
4. Select "Enter Multiple Emails Separated with Comma".
5. Verify one or more email addresses are configured.

If "Log Collector Error" alarm type is not enabled or email addresses are not configured to receive the alert, this is a finding.
Fix Text (F-45826r714091_fix)
Configure Cisco ISE to notify one or more individuals when there is a Log Collection Error.

From the Web Admin portal:
1. Choose Administration >> System >> Settings >> Alarm Settings.
2. Select "Log Collector Error" from the list of default alarms and click "Edit".
3. Select "Enable".
4. Select "Enter Multiple Emails Separated with Comma".
5. Configure email addresses of individuals and organizational accounts to be notified.
6. Click "Submit".