STIGhubSTIGhub
STIGsRMF ControlsCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • RMF Controls
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 4 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Cisco ISE NAC Security Technical Implementation Guide

V-242577

CAT I (High)

The Cisco ISE must be configured to profile endpoints connecting to the network. This is required for compliance with C2C Step 4.

Rule ID

SV-242577r1146387_rule

STIG

Cisco ISE NAC Security Technical Implementation Guide

Version

V2R3

CCIs

CCI-000213

Discussion

It is possible for endpoints to be manually added to an incorrect endpoint identity group. The endpoint policy can be dynamically set through profiling. If the endpoint group is statically set but the endpoint policy is set to dynamic, then it is possible to identify endpoints that may receive unintended access.

Check Content

If DoD is not at C2C Step 4 or higher, this is not a finding.

Verify the profiling service is configured and enabled.

1. Choose Administration >> System >> Deployment.
2. View the Deployment Nodes.

Verify the following services are enabled via the check box:
Policy Service
Enable Session Services 
Enable Profiling Services

If the Cisco ISE profiling service is not configured and enabled, this is a finding.

Fix Text

Configure the profiling service to provide a contextual inventory of all the endpoints that are using your network resources in any Cisco ISE-enabled network.

1. Choose Administration >> System >> Deployment.
2. Choose a Cisco ISE node that assumes the Policy Service persona.
3. Click "Edit" in the Deployment Nodes page.
4. On the "General Settings" tab, check the "Policy Service" check box.
5. Perform the following tasks:
- Check the "Enable Session Services" check box. 
- Check the "Enable Profiling Services" check box to run the profiling service.
6. Click "Save" to save the node configuration.