Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Customer Secure Configuration Requirements

Identity & Access Management (IA-2, IA‑5, AC-5, AC‑2)

Configuration for SSO/SAML integration

Customers should:

Network Device Configuration (CM-6, AC-6, AC-17)

The following are device-specific configuration for FedRAMP-recommended security policies:

Access Points (APs)

Customers should:

Mist Edge

Customers should use Mist Edge best practices.

Wireless Configuration (AC-18, SC-18, SC-13)

Customers should configure all WLAN security settings.

SSID Security

Customer should use WPA2 Enterprise for internal networks.

Logging & Monitoring (AU-2, AU-6, SI-6, SI-4)

Customers should configure audit logs to be forwarded directly to an agency SIEM or exported via API for ingestion into their chosen log‑management or SIEM platform.

Encryption (SC-12, SC‑13)

Customer should:

  • Use TLS 1.2+ for API integrations.

  • Follow FedRAMP guidelines for FIPS.

API Security (AC-3, IA-3, IA‑5)

Customers should:

  • Use API tokens based on RBAC privileges required.
  • Rotate tokens every 90 days.
  • Store tokens in a secure secrets manager.
  • Disable unused tokens immediately.
  • Use HTTPS and SSL verification for webhooks (if applicable).

Change Management (CM-3, CM-4)

Customers should document all Mist configuration changes.

Vulnerability Management (RA-5, SI-5, SI-2)

Customers should:

Backup & Recovery (CP-9, CP-10)

Customers should perform customer organization configuration API backups per FedRAMP guidelines.