ON THIS PAGE
Customer Secure Configuration Requirements
Identity & Access Management (IA-2, IA‑5, AC-5, AC‑2)
Configuration for SSO/SAML integration
Customers should:
- Configure MFA for agency accounts (required for FedRAMP)
- Configure SAML/SSO integration with agency identity provider strongly recommended.
- Configure Role based access control (RBAC)
- Disable unused local accounts as per FedRAMP guidelines.
- Review user access as per FedRAMP guidelines.
Network Device Configuration (CM-6, AC-6, AC-17)
The following are device-specific configuration for FedRAMP-recommended security policies:
Access Points (APs)
Customers should:
- Configure SSID encryption for WLAN
- Enable rogue AP detection and alerting. See Juniper Mist Alert Types.
-
Apply Mist recommended firmware and recommended security alerts.
Mist Edge
Customers should use Mist Edge best practices.
Wireless Configuration (AC-18, SC-18, SC-13)
Customers should configure all WLAN security settings.
SSID Security
Customer should use WPA2 Enterprise for internal networks.
Logging & Monitoring (AU-2, AU-6, SI-6, SI-4)
Customers should configure audit logs to be forwarded directly to an agency SIEM or exported via API for ingestion into their chosen log‑management or SIEM platform.
Encryption (SC-12, SC‑13)
Customer should:
-
Use TLS 1.2+ for API integrations.
-
Follow FedRAMP guidelines for FIPS.
API Security (AC-3, IA-3, IA‑5)
Customers should:
- Use API tokens based on RBAC privileges required.
- Rotate tokens every 90 days.
- Store tokens in a secure secrets manager.
- Disable unused tokens immediately.
- Use HTTPS and SSL verification for webhooks (if applicable).
Change Management (CM-3, CM-4)
Customers should document all Mist configuration changes.
Vulnerability Management (RA-5, SI-5, SI-2)
Customers should:
- Review Mist provided security advisories.
- Apply firmware updates as recommended by Juniper Mist.
Backup & Recovery (CP-9, CP-10)
Customers should perform customer organization configuration API backups per FedRAMP guidelines.