Cisco ASA NDM STIG Version Comparison
Cisco ASA NDM Security Technical Implementation Guide
Comparison
There are 2 differences between versions v1 r6 (Oct. 25, 2023) (the "left" version) and v2 r2 (Oct. 24, 2024) (the "right" version).
Check CASA-ND-001260 was removed from the benchmark in the "right" version. The text below reflects the old wording.
This check's original form is available here.
Text Differences
Title
The Cisco ASA must be configured to offload audit records onto a different system or media than the system being audited.
Check Content
Review the Cisco ASA configuration to verify it is compliant with this requirement as shown in the example below. logging trap notifications logging host NDM_INTERFACE 10.1.48.10 6/1514 Note: A logging list can be used as an alternative to the severity level. If the Cisco ASA is not configured to offload log records onto a different system than the system being audited, this is a finding.
Discussion
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Offloading is a common process in information systems with limited audit storage capacity.
Fix
Configure the Cisco ASA to send log records to a syslog server as shown in the example below. ASA(config)# logging host NDM_INTERFACE 10.1.48.10 6/1514 ASA(config)# logging trap notifications ASA(config)# end