# DISA Releases Cisco SNA STIG

The Defense Information Systems Agency (DISA) issued a product-specific Security Technical Implementation Guide (STIG) for Cisco Secure Network Analytics (SNA) in June 2026, establishing 31 detailed security requirements to ensure compliance with Zero Trust policies and the Risk Management Framework. This STIG provides a standardized, repeatable baseline for securely configuring Cisco's network detection and response platform, emphasizing secure platform setup, auditability, and continuous compliance. Federal and defense contractors deploying or managing Cisco SNA must integrate these requirements into their cybersecurity and procurement processes to meet DISA standards and support federal cybersecurity mandates.

- **Why this matters:** Contractors working with Cisco SNA in defense environments must comply with the new STIG to ensure contract eligibility and maintain cybersecurity standards.
- The STIG translates high-level Zero Trust policies into specific, testable configuration requirements, facilitating consistent implementation and assessment.
- Procurement professionals should incorporate these requirements into acquisition planning and vendor evaluations to align with DISA and DoD cybersecurity mandates.
- Organizations managing administrative access to Cisco SNA must enforce explicit authorization and strong authentication as outlined in the STIG to meet compliance.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity
**Published:** September 15, 2026

### Government Entities
- Defense Information Systems Agency (DISA)
- Department of Defense (DoD)
- National Institute of Standards and Technology (NIST)

### Vendors
- Cisco (Developer and vendor of Secure Network Analytics platform)

### Key Quotes
> The STIG converts cybersecurity policy into specific, testable configuration requirements that administrators and assessors can apply consistently.
> — Norman St. Laurent, Federal Product Marketing Manager

> Administrative access should be explicitly authorized, strongly authenticated, and limited to the privileges required for the role.
> — Jim Kotantoulas, DoD Cisco Security Engineer

### Sources
- [Cisco and the DISA STIG: Turning Zero Trust Policy into Repeatable Practice - Part 2: Cisco SNA - Cisco Blogs](https://blogs.cisco.com/industries/cisco-and-the-disa-stig-turning-zero-trust-policy-into-repeatable-practice-part-2-cisco-sna) - Cisco Blogs