The Cisco ISE must be configured to profile endpoints connecting to the network. This is required for compliance with C2C Step 4.
An XCCDF Rule
Description
<VulnDiscussion>It is possible for endpoints to be manually added to an incorrect endpoint identity group. The endpoint policy can be dynamically set through profiling. If the endpoint group is statically set but the endpoint policy is set to dynamic, then it is possible to identify endpoints that may receive unintended access.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-242577r812736_rule
- Severity
- High
- References
- Updated
Remediation - Manual Procedure
Configure the profiling service to provide a contextual inventory of all the endpoints that are using your network resources in any Cisco ISE-enabled network.
1. Choose Administration >> System >> Deployment.
2. Choose a Cisco ISE node that assumes the Policy Service persona.
3. Click "Edit" in the Deployment Nodes page.
4. On the "General Settings" tab, check the "Policy Service" check box.